Show filters
45 Total Results
Displaying 41-45 of 45
Sort by:
Attacker Value
Unknown
CVE-2017-7981
Disclosure Date: April 29, 2017 (last updated November 26, 2024)
Tuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin. This occurs in the Project Wiki component because the proc_open PHP function is used within PhpWiki before 1.5.5 with a syntax value in its first argument, and an authenticated Tuleap user can control this value, even with shell metacharacters, as demonstrated by a '<?plugin SyntaxHighlighter syntax="c;id"' line to execute the id command.
0
Attacker Value
Unknown
CVE-2014-8791
Disclosure Date: December 02, 2014 (last updated October 05, 2023)
project/register.php in Tuleap before 7.7, when sys_create_project_in_one_step is disabled, allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP code via the data parameter.
0
Attacker Value
Unknown
CVE-2014-7178
Disclosure Date: November 28, 2014 (last updated October 05, 2023)
Enalean Tuleap before 7.5.99.6 allows remote attackers to execute arbitrary commands via the User-Agent header, which is provided to the passthru PHP function.
0
Attacker Value
Unknown
CVE-2014-7176
Disclosure Date: November 04, 2014 (last updated October 05, 2023)
SQL injection vulnerability in Enalean Tuleap before 7.5.99.4 allows remote authenticated users to execute arbitrary SQL commands via the lobal_txt parameter to plugins/docman.
0
Attacker Value
Unknown
CVE-2014-7177
Disclosure Date: October 31, 2014 (last updated October 05, 2023)
XML External Entity vulnerability in Enalean Tuleap 7.2 and earlier allows remote authenticated users to read arbitrary files via a crafted xml document in a create action to plugins/tracker/.
0