{
    "id": "CVE-2014-1683",
    "published": "2014-01-29 18:55:27",
    "last_modified": "2026-06-17 00:05:22",
    "cvss_score": "6.8",
    "cvss_severity": "MEDIUM",
    "cvss_version": "2.0",
    "cvss_vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
    "cwe": "CWE-134",
    "description": "The bashMail function in cms/data/skins/techjunkie/fragments/contacts/functions.php in SkyBlueCanvas CMS before 1.1 r248-04, when the pid parameter is 4, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) name, (2) email, (3) subject, or (4) message parameter to index.php.",
    "epss_score": "0.31415",
    "epss_percentile": "0.98226",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-09-27 18:17:12",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "skybluecanvas",
            "product": "skybluecanvas"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "31432",
            "title": "Skybluecanvas CMS - Remote Code Execution (Metasploit)",
            "date": "2014-02-05",
            "url": "https://www.exploit-db.com/exploits/31432"
        },
        {
            "source": "exploit-db",
            "ref_id": "31183",
            "title": "Skybluecanvas CMS 1.1 r248-03 - Remote Command Execution",
            "date": "2014-01-24",
            "url": "https://www.exploit-db.com/exploits/31183"
        }
    ],
    "refs_list": [
        "http://packetstormsecurity.com/files/124948/SkyBlueCanvas-CMS-1.1-r248-03-Command-Injection.html",
        "http://seclists.org/fulldisclosure/2014/Jan/159",
        "http://secunia.com/advisories/56646",
        "http://www.exploit-db.com/exploits/31183",
        "http://www.exploit-db.com/exploits/31432",
        "http://www.securityfocus.com/bid/65129",
        "https://exchange.xforce.ibmcloud.com/vulnerabilities/90670",
        "http://packetstormsecurity.com/files/124948/SkyBlueCanvas-CMS-1.1-r248-03-Command-Injection.html",
        "http://seclists.org/fulldisclosure/2014/Jan/159",
        "http://secunia.com/advisories/56646",
        "http://www.exploit-db.com/exploits/31183",
        "http://www.exploit-db.com/exploits/31432",
        "http://www.securityfocus.com/bid/65129",
        "https://exchange.xforce.ibmcloud.com/vulnerabilities/90670"
    ]
}