// For flags

CVE-2014-2996

XCloner Standalone 3.5 - Cross-Site Request Forgery

Severity Score

7.2
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

3
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

XCloner Standalone 3.5 and earlier, when enable_db_backup and sql_mem are enabled, allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the dbbackup_comp parameter in a generate action to index2.php. NOTE: it is not clear whether this issue crosses privilege boundaries, since administrators might already have the privileges to execute code. NOTE: this can be leveraged by remote attackers using CVE-2014-2579.

XCloner Standalone 3.5 y anteriores, cuando enable_db_backup y sql_mem están habilitados, permite a administradores remotos autenticados ejecutar comandos arbitrarios a través de metacaracteres de shell en el parámetro dbbackup_comp en una acción generate hacia index2.php. NOTA: ino está claro si este problema cruza límites de privilegio, como administradores podrían ya tener los privilegios para ejecutar código. NOTA: esto puede ser aprovechado por atacantes remotos utilizando CVE-2014-2579.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
High
Authentication
Single
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2014-04-10 First Exploit
  • 2014-04-25 CVE Reserved
  • 2014-04-25 CVE Published
  • 2024-08-06 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Xcloner
Search vendor "Xcloner"
Xcloner
Search vendor "Xcloner" for product "Xcloner"
<= 3.5
Search vendor "Xcloner" for product "Xcloner" and version " <= 3.5"
standalone
Affected