CVE-2014-2302
19.07.2018, 17:29
The installer script in webEdition CMS before 6.2.7-s1 and 6.3.x before 6.3.8-s1 allows remote attackers to conduct PHP Object Injection attacks by intercepting a request to update.webedition.org.
Vendor | Product | Version |
---|---|---|
webedition | webedition_cms | 𝑥 < 6.2.7.0 |
webedition | webedition_cms | 6.3.0 ≤ 𝑥 < 6.3.8 |
webedition | webedition_cms | 6.2.7.0:s1 |
webedition | webedition_cms | 6.3.8:s1 |
𝑥
= Vulnerable software versions
References