CVE-2014-7178: Input Validation
Published Nov 28, 2014
·Updated
Enalean Tuleap before 7.5.99.6 allows remote attackers to execute arbitrary commands via the User-Agent header, which is provided to the passthru PHP function.
Affected Software
1 affected component
Enalean Tuleap<=7.5.99.5
Event History
Nov 28, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-7178?
CVE-2014-7178 is rated as a high severity vulnerability due to the potential for remote command execution.
2
How do I fix CVE-2014-7178?
To fix CVE-2014-7178, update Enalean Tuleap to version 7.5.99.6 or later.
3
What type of attacks can exploit CVE-2014-7178?
CVE-2014-7178 can be exploited by attackers using crafted User-Agent headers to execute arbitrary commands.
4
Which versions of Enalean Tuleap are affected by CVE-2014-7178?
Enalean Tuleap versions prior to 7.5.99.6, specifically up to 7.5.99.5, are affected by CVE-2014-7178.
5
Is CVE-2014-7178 a client-side or server-side vulnerability?
CVE-2014-7178 is a server-side vulnerability as it allows remote attackers to compromise the server through forged requests.