CVE-2014-2935: OS Command Injection
Published May 8, 2014
·Updated
costview3/xmlrpcserver/xmlrpc.php in CostView in Caldera 9.20 allows remote attackers to execute arbitrary commands via shell metacharacters in a methodCall element in a PHP XMLRPC request.
Affected Software
1 affected component
Caldera Caldera=9.20
Event History
May 8, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
via NVD·10:55 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-2935?
CVE-2014-2935 is considered to have a high severity due to the possibility of remote command execution.
2
How do I fix CVE-2014-2935?
To fix CVE-2014-2935, you should update Caldera to a version that addresses this vulnerability.
3
What type of attacks can exploit CVE-2014-2935?
CVE-2014-2935 can be exploited by attackers sending crafted PHP XMLRPC requests that include shell metacharacters.
4
Which software is affected by CVE-2014-2935?
CVE-2014-2935 specifically affects Caldera version 9.20.
5
What is the impact of CVE-2014-2935?
The impact of CVE-2014-2935 allows unauthorized remote execution of commands on the affected server.