CVE-2014-8677
MEDIUMsoplanning < 1.32 - Authenticated Remote Code Execution via Crafted Database Name
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-8677. PoCs published by Huy-Ngoc DAU.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in SOPlanning 1.32 and prior, including SQL injection, XSS, path traversal, authentication hash disclosure, and PHP code injection during installation. It provides detailed proof-of-concept examples for each vulnerability.
Description
The installation process for SOPlanning 1.32 and earlier allows remote authenticated users with a prepared database, and access to an existing database with a crafted name, or permissions to create arbitrary databases, or if PHP before 5.2 is being used, the configuration database is down, and smarty/templates_c is not writable to execute arbitrary php code via a crafted database name.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in SOPlanning 1.32 and prior, including SQL injection, XSS, path traversal, authentication hash disclosure, and PHP code injection during installation. It provides detailed proof-of-concept examples for each vulnerability.
References (4)
Scores
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N