CVE-2014-5519: Code Injection
The Ploticus module in PhpWiki 1.5.0 allows remote attackers to execute arbitrary code via shell metacharacters in a device option in the edit[content] parameter to index.php/HeIp. NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5519?
CVE-2014-5519 is considered a high severity vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2014-5519?
To mitigate CVE-2014-5519, upgrade PhpWiki to a version that is not affected by this vulnerability, as no specific patch is provided for version 1.5.0.
What causes CVE-2014-5519?
CVE-2014-5519 is caused by improper handling of shell metacharacters in the Ploticus module of PhpWiki.
Which versions of PhpWiki are affected by CVE-2014-5519?
CVE-2014-5519 specifically affects PhpWiki version 1.5.0.
Can CVE-2014-5519 be exploited remotely?
Yes, CVE-2014-5519 allows remote attackers to exploit the vulnerability through crafted input.