CVE-2014-1683
29.01.2014, 18:55
The bashMail function in cms/data/skins/techjunkie/fragments/contacts/functions.php in SkyBlueCanvas CMS before 1.1 r248-04, when the pid parameter is 4, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) name, (2) email, (3) subject, or (4) message parameter to index.php.Enginsight
| Vendor | Product | Version |
|---|---|---|
| skybluecanvas | skybluecanvas | 𝑥 ≤ 1.1_r248-03 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References