CVE-2014-2936: Code Injection
Published May 8, 2014
·Updated
The directory manager in Caldera 9.20 allows remote attackers to conduct variable-injection attacks in the global scope via (1) the maindirhotfolder parameter to dirmng/index.php, or an unspecified parameter to (2) PPD/index.php, (3) dirmng/docmd.php, or (4) dirmng/param.php.
Affected Software
1 affected component
Caldera Caldera=9.20
Event History
May 8, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
via NVD·10:55 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-2936?
CVE-2014-2936 is classified as a medium severity vulnerability.
2
How does CVE-2014-2936 impact system security?
CVE-2014-2936 allows remote attackers to conduct variable-injection attacks, potentially compromising the application's global scope.
3
How do I fix CVE-2014-2936?
To fix CVE-2014-2936, update Caldera to the latest version or apply security patches that address this vulnerability.
4
Which versions of Caldera are affected by CVE-2014-2936?
CVE-2014-2936 affects Caldera version 9.20.
5
Are there any known exploits for CVE-2014-2936?
Yes, there are known exploits for CVE-2014-2936 that demonstrate how to execute variable-injection attacks.