CVE-2014-1683 EXPLOIT
6.8
MEDIUM · CVSS 2.0 · EPSS 31.4% (pctl 98)
Patch early
A public exploit exists.
Description
The bashMail function in cms/data/skins/techjunkie/fragments/contacts/functions.php in SkyBlueCanvas CMS before 1.1 r248-04, when the pid parameter is 4, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) name, (2) email, (3) subject, or (4) message parameter to index.php.
Scoring
| CVSS | 6.8 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
| EPSS | 31.42% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-134 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2014-01-29 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| skybluecanvas | skybluecanvas |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Skybluecanvas CMS - Remote Code Execution (Metasploit) | 2014-02-05 |
| exploit-db | Skybluecanvas CMS 1.1 r248-03 - Remote Command Execution | 2014-01-24 |
References
- http://packetstormsecurity.com/files/124948/SkyBlueCanvas-CMS-1.1-r248-03-Command-Injection.html
- http://seclists.org/fulldisclosure/2014/Jan/159
- http://secunia.com/advisories/56646
- http://www.exploit-db.com/exploits/31183
- http://www.exploit-db.com/exploits/31432
- http://www.securityfocus.com/bid/65129
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90670
- http://packetstormsecurity.com/files/124948/SkyBlueCanvas-CMS-1.1-r248-03-Command-Injection.html
- http://seclists.org/fulldisclosure/2014/Jan/159
- http://secunia.com/advisories/56646
- http://www.exploit-db.com/exploits/31183
- http://www.exploit-db.com/exploits/31432
- http://www.securityfocus.com/bid/65129
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90670
→ the Explorer · watch your stack · NVD