CVE Vulnerabilities

CVE-2014-1217

Published: Apr 28, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Livetecs Timelive before 6.2.8 does not properly restrict access to systemsetting.aspx, which allows remote attackers to change configurations and obtain the database connection string and credentials via unspecified vectors.

Affected Software

NameVendorStart VersionEnd Version
TimelineLivetecs2.81 (including)2.81 (including)
TimelineLivetecs2.91 (including)2.91 (including)
TimelineLivetecs2.94 (including)2.94 (including)
TimelineLivetecs3.0.1 (including)3.0.1 (including)
TimelineLivetecs3.0.3 (including)3.0.3 (including)
TimelineLivetecs3.0.5 (including)3.0.5 (including)
TimelineLivetecs3.1.1 (including)3.1.1 (including)
TimelineLivetecs3.2.1 (including)3.2.1 (including)
TimelineLivetecs3.5.1 (including)3.5.1 (including)
TimelineLivetecs3.6.1 (including)3.6.1 (including)
TimelineLivetecs3.7.1 (including)3.7.1 (including)
TimelineLivetecs3.8.1 (including)3.8.1 (including)
TimelineLivetecs4.2.1 (including)4.2.1 (including)
TimelineLivetecs4.3.1 (including)4.3.1 (including)
TimelineLivetecs4.9.1 (including)4.9.1 (including)
TimelineLivetecs5.2.1 (including)5.2.1 (including)
TimelineLivetecs6.0.1 (including)6.0.1 (including)
TimelineLivetecs6.2.1 (including)6.2.1 (including)
TimelineLivetecs6.2.3 (including)6.2.3 (including)
TimelineLivetecs6.2.4 (including)6.2.4 (including)
TimelineLivetecs6.2.6 (including)6.2.6 (including)
TimelineLivetecs6.2.7 (including)6.2.7 (including)
TimelineLivetecs6.2.71 (including)6.2.71 (including)
TimelineLivetecs7.1.1 (including)7.1.1 (including)

References