CVE-2014-2921
Pimcore CMS 1.4.9 <2.1.0 - Multiple Vulnerabilities
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
The getObjectByToken function in Newsletter.php in the Pimcore_Tool_Newsletter module in pimcore 1.4.9 through 2.0.0 does not properly handle an object obtained by unserializing Lucene search data, which allows remote attackers to conduct PHP object injection attacks and execute arbitrary code via vectors involving a Zend_Pdf_ElementFactory_Proxy object and a pathname with a trailing \0 character.
La función getObjectByToken en Newsletter.php en el módulo Pimcore_Tool_Newsletter en pimcore 1.4.9 hasta 2.0.0 no maneja debidamente un objeto obtenido deserializando dotas de búsqueda Lucene, lo que permite a atacantes remotos realizar ataques de inyección de objetos PHP y ejecutar código arbitrario a través de vectores involucrando un objeto Zend_Pdf_ElementFactory_Proxy y un nombre de ruta con un caracter \0 final.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-04-21 CVE Reserved
- 2014-04-21 CVE Published
- 2014-10-12 First Exploit
- 2024-04-19 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://openwall.com/lists/oss-security/2014/04/21/1 | Mailing List |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/43886 | 2014-10-12 | |
https://github.com/pedrib/PoC/blob/master/pimcore-2.1.0.txt | 2024-08-06 |
URL | Date | SRC |
---|---|---|
http://www.pimcore.org/en/resources/blog/pimcore+2.2+released_b442 | 2014-04-22 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Pimcore Search vendor "Pimcore" | Pimcore Search vendor "Pimcore" for product "Pimcore" | 1.4.9 Search vendor "Pimcore" for product "Pimcore" and version "1.4.9" | - |
Affected
| ||||||
Pimcore Search vendor "Pimcore" | Pimcore Search vendor "Pimcore" for product "Pimcore" | 1.5.0 Search vendor "Pimcore" for product "Pimcore" and version "1.5.0" | - |
Affected
| ||||||
Pimcore Search vendor "Pimcore" | Pimcore Search vendor "Pimcore" for product "Pimcore" | 2.1.0 Search vendor "Pimcore" for product "Pimcore" and version "2.1.0" | - |
Affected
| ||||||
Pimcore Search vendor "Pimcore" | Pimcore Search vendor "Pimcore" for product "Pimcore" | 2.2.0 Search vendor "Pimcore" for product "Pimcore" and version "2.2.0" | - |
Affected
|