peter bassill · operator
$ cve CVE-2014-1683 JSON

CVE-2014-1683 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 31.4% (pctl 98)

Patch early

A public exploit exists.

Description

The bashMail function in cms/data/skins/techjunkie/fragments/contacts/functions.php in SkyBlueCanvas CMS before 1.1 r248-04, when the pid parameter is 4, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) name, (2) email, (3) subject, or (4) message parameter to index.php.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS31.42% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-134
On CISA KEVno
Public exploityes
Published2014-01-29
Last modified2026-06-17

Affected (1)

VendorProduct
skybluecanvasskybluecanvas

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD