Description
htdocs/setup/index.php in Eventum before 2.3.5 allows remote attackers to inject and execute arbitrary PHP code via the hostname parameter.
In plain language
AI Worth attentionEventum versions before 2.3.5 have a serious flaw that can let an outsider take over the application, so small businesses using it should act promptly.
Unauthenticated remote PHP code injection in Eventum’s setup page allows arbitrary code execution through the hostname parameter.
What to do now
- Check whether you run Eventum and confirm its installed version is earlier than 2.3.5.
- Upgrade Eventum to version 2.3.5 or later.
- Until upgraded, restrict access to the Eventum setup page so it cannot be reached by untrusted users.
- Ask your IT provider to review the server for unexpected changes to Eventum files or settings.
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2014-1632 and every CVE in our database. Create a free account — no credit card required.
Create Free Account