CVE-2014-8791
Tuleap <7.7 - Code Injection
Title source: llmDescription
project/register.php in Tuleap before 7.7, when sys_create_project_in_one_step is disabled, allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP code via the data parameter.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotephp
https://www.exploit-db.com/exploits/35545
metasploit
WORKING POC
EXCELLENT
rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/tuleap_unserialize_exec.rb
References (5)
Scores
EPSS
0.5240
EPSS Percentile
97.9%
Details
CWE
CWE-94
Status
published
Products (1)
enalean/tuleap
7.6
Published
Dec 02, 2014
Tracked Since
Feb 18, 2026