Zikula Application Framework before 1.3.7 build 11 allows remote attackers to conduct PHP object injection attacks and delete arbitrary files or execute arbitrary PHP code via crafted serialized data in the (1) authentication_method_ser or (2) authentication_info_ser parameter to index.php, or (3) zikulaMobileTheme parameter to index.php.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2018-03-26T18:00:00
Updated: 2024-08-06T10:06:00.304Z
Reserved: 2014-03-06T00:00:00
Link: CVE-2014-2293
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-03-26T18:29:00.300
Modified: 2024-11-21T02:06:01.250
Link: CVE-2014-2293
Redhat
No data.