CVE-2014-1631
HIGHEventum < 2.3.5 - Unauthenticated Application Reinstallation via Direct Setup Request
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2014-1631. PoCs published by High-Tech Bridge.
AI-analyzed exploit summary The advisory describes two vulnerabilities in Eventum 2.3.4: incorrect default permissions allowing reinstallation via an exposed setup script (CVE-2014-1631) and code injection via the 'hostname' parameter during installation (CVE-2014-1632). The latter enables arbitrary PHP execution if the attacker controls the MySQL server.
Description
Eventum before 2.3.5 allows remote attackers to reinstall the application via direct request to /setup/index.php.
Exploits (2)
The advisory describes two vulnerabilities in Eventum 2.3.4: incorrect default permissions allowing reinstallation via an exposed setup script (CVE-2014-1631) and code injection via the 'hostname' parameter during installation (CVE-2014-1632). The latter enables arbitrary PHP execution if the attacker controls the MySQL server.
The provided text describes an insecure file-permission vulnerability in Eventum 2.3.4, allowing an attacker to reinstall the application via an exposed setup page. No actual exploit code is included, only a reference to a URI.
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N