VWE-2014-0232 Printable Version

https://www.vaultwiki.org/pages/Book/Documentation/VWE-2014-0232
This page is a chapter in Info Known Vulnerabilities

This page has been seen 4,710 times.

    • Created by on
Common NameNone
VWE-IDVWE-2014-0232
Related ReportNone
SeverityExtreme
Exploit DifficultyEASY
PlatformAffects all platforms supported by the vulnerable versions.
DescriptionArbitrary code execution. By entering a specially-crafted URL inside an IMG BB-Code tag within wiki content rendered to a plain-text format, a malicious user can execute arbitrary PHP code on the server. Does not affect Lite versions.
DiscoveredAugust 2, 2014
ResolvedDecember 1, 2014
Patches Available3.0.21
The versions listed below are known to be affected by this issue. If you are using one of those versions, you should update to a newer release that has no known vulnerabilities.