CVE Vulnerabilities

CVE-2014-0342

Published: Apr 15, 2014 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Multiple unrestricted file upload vulnerabilities in fileupload.php in PivotX before 2.3.9 allow remote authenticated users to execute arbitrary PHP code by uploading a file with a (1) .php or (2) .php# extension, and then accessing it via unspecified vectors.

Affected Software

Name Vendor Start Version End Version
Pivotx Pivotx * 2.3.8 (including)
Pivotx Pivotx 2.1.0 (including) 2.1.0 (including)
Pivotx Pivotx 2.1.1 (including) 2.1.1 (including)
Pivotx Pivotx 2.1.2 (including) 2.1.2 (including)
Pivotx Pivotx 2.2.0 (including) 2.2.0 (including)
Pivotx Pivotx 2.2.0-b1 (including) 2.2.0-b1 (including)
Pivotx Pivotx 2.2.0-b2 (including) 2.2.0-b2 (including)
Pivotx Pivotx 2.2.0-rc (including) 2.2.0-rc (including)
Pivotx Pivotx 2.2.1 (including) 2.2.1 (including)
Pivotx Pivotx 2.2.2 (including) 2.2.2 (including)
Pivotx Pivotx 2.2.3 (including) 2.2.3 (including)
Pivotx Pivotx 2.2.5 (including) 2.2.5 (including)
Pivotx Pivotx 2.3.0 (including) 2.3.0 (including)
Pivotx Pivotx 2.3.2 (including) 2.3.2 (including)
Pivotx Pivotx 2.3.3 (including) 2.3.3 (including)
Pivotx Pivotx 2.3.5 (including) 2.3.5 (including)
Pivotx Pivotx 2.3.6 (including) 2.3.6 (including)
Pivotx Pivotx 2.3.7 (including) 2.3.7 (including)

References