CVE-2014-7985: Path Traversal
Published Oct 31, 2014
·Updated
Directory traversal vulnerability in EspoCRM before 2.6.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the action parameter to install/index.php.
Affected Software
1 affected component
EspoCRM EspoCRM<=2.5.2
Remediation
Patch Available
Event History
Oct 31, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-7985?
CVE-2014-7985 is considered a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2014-7985?
To fix CVE-2014-7985, upgrade EspoCRM to version 2.6.0 or later.
3
What does CVE-2014-7985 allow an attacker to do?
CVE-2014-7985 allows remote attackers to execute arbitrary local files on the server.
4
Which versions of EspoCRM are affected by CVE-2014-7985?
EspoCRM versions before 2.6.0, specifically up to version 2.5.2, are affected by CVE-2014-7985.
5
What type of vulnerability is CVE-2014-7985?
CVE-2014-7985 is a directory traversal vulnerability.