CVE-2014-2996

XCloner Standalone 3.5 and earlier, when enable_db_backup and sql_mem are enabled, allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the dbbackup_comp parameter in a generate action to index2.php.  NOTE: it is not clear whether this issue crosses privilege boundaries, since administrators might already have the privileges to execute code.  NOTE: this can be leveraged by remote attackers using CVE-2014-2579.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.1 UNKNOWN
NETWORK
HIGH
AV:N/AC:H/Au:S/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---