CVE-2014-7178

Enalean Tuleap <7.5.99.6 - RCE

Title source: llm
STIX 2.1

Description

Enalean Tuleap before 7.5.99.6 allows remote attackers to execute arbitrary commands via the User-Agent header, which is provided to the passthru PHP function.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Portcullis · textwebappsphp
https://www.exploit-db.com/exploits/35100

References (3)

Core 3

Scores

EPSS 0.1039
EPSS Percentile 93.2%

Details

CWE
CWE-20
Status published
Products (1)
enalean/tuleap < 7.5.99.5
Published Nov 28, 2014
Tracked Since Feb 18, 2026