Back to search
CVE-2014-8677
Published: Aug 31, 2017
Modified: Aug 6, 2024
PUBLISHED
Description
The installation process for SOPlanning 1.32 and earlier allows remote authenticated users with a prepared database, and access to an existing database with a crafted name, or permissions to create arbitrary databases, or if PHP before 5.2 is being used, the configuration database is down, and smarty/templates_c is not writable to execute arbitrary php code via a crafted database name.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
75726
vdb-entry
x_refsource_BID
20150710 SOPlanning - Simple Online Planning Tool multiple vulnerabilities
mailing-list
x_refsource_FULLDISC
37604
exploit
x_refsource_EXPLOIT-DB
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now