Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
EGroupware Enterprise Line (EPL) before 1.1.20140505, EGroupware Community Edition before 1.8.007.20140506, and EGroupware before 14.1 beta allows remote authenticated administrators to execute arbitrary PHP code via crafted callback values to the call_user_func PHP function, as demonstrated using the newsettings[system] parameter. NOTE: this can be exploited by remote attackers by leveraging CVE-2014-2987.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
多款Stylite EGroupware产品代码注入漏洞
Vulnerability Description
Stylite EGroupware是德国Stylite公司的一套基于PHP的团队协作软件。该软件包括电子邮件(IMAP/POP3)、通讯录、文档管理、书签等模块。EGroupware Enterprise Line(EPL)是一个企业在线版;EGroupware Community Edition是一个社区版。 多款Stylite EGroupware产品中存在安全漏洞。远程攻击者可借助call_user_func PHP函数中特制的‘callback’值利用该漏洞执行任意PHP代码。以下产品和版本受到
CVSS Information
N/A
Vulnerability Type
N/A