CVE-2014-8684 EXPLOIT
9.8
CRITICAL · CVSS 3.0 · EPSS 71.7% (pctl 99)
Patch early
A public exploit exists.
Description
CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and consequently conduct PHP object injection attacks by leveraging use of standard string comparison operators to compare cryptographic hashes.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 71.71% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-310 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2017-09-19 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| codeigniter | codeigniter |
| kohanaframework | kohana |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Seagate Business NAS - Remote Command Execution (Metasploit) | 2015-03-04 |
References
- http://packetstormsecurity.com/files/130609/Seagate-Business-NAS-Unauthenticated-Remote-Command-Execution.html
- http://seclists.org/fulldisclosure/2014/May/54
- https://github.com/kohana/core/pull/492
- https://scott.arciszewski.me/research/full/php-framework-timing-attacks-object-injection
- http://packetstormsecurity.com/files/130609/Seagate-Business-NAS-Unauthenticated-Remote-Command-Execution.html
- http://seclists.org/fulldisclosure/2014/May/54
- https://github.com/kohana/core/pull/492
- https://scott.arciszewski.me/research/full/php-framework-timing-attacks-object-injection
→ the Explorer · watch your stack · NVD