CVE-2014-2996 EXPLOIT
7.1
HIGH · CVSS 2.0 · EPSS 9.9% (pctl 95)
Patch early
A public exploit exists.
Description
XCloner Standalone 3.5 and earlier, when enable_db_backup and sql_mem are enabled, allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the dbbackup_comp parameter in a generate action to index2.php. NOTE: it is not clear whether this issue crosses privilege boundaries, since administrators might already have the privileges to execute code. NOTE: this can be leveraged by remote attackers using CVE-2014-2579.
Scoring
| CVSS | 7.1 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:H/Au:S/C:C/I:C/A:C |
| EPSS | 9.92% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-94 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2014-04-25 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| xcloner | xcloner |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | XCloner Standalone 3.5 - Cross-Site Request Forgery | 2014-04-10 |
References
→ the Explorer · watch your stack · NVD