peter bassill · operator
$ cve CVE-2014-2996 JSON

CVE-2014-2996 EXPLOIT

7.1
HIGH · CVSS 2.0 · EPSS 9.9% (pctl 95)

Patch early

A public exploit exists.

Description

XCloner Standalone 3.5 and earlier, when enable_db_backup and sql_mem are enabled, allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the dbbackup_comp parameter in a generate action to index2.php. NOTE: it is not clear whether this issue crosses privilege boundaries, since administrators might already have the privileges to execute code. NOTE: this can be leveraged by remote attackers using CVE-2014-2579.

Scoring

CVSS7.1 (HIGH, v2.0)
VectorAV:N/AC:H/Au:S/C:C/I:C/A:C
EPSS9.92% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2014-04-25
Last modified2026-06-17

Affected (1)

VendorProduct
xclonerxcloner

Public exploits

SourceTitleDate
exploit-dbXCloner Standalone 3.5 - Cross-Site Request Forgery2014-04-10

References

→ the Explorer  ·  watch your stack  ·  NVD