« Volver al listado

CVE-2014-5297

Estado: ModificadaAlta (7.5)—

El método actionSendErrorReport en protected/controllers/SiteController.php en X2Engine 2.8 hasta 4.1.7 permite a atacantes remotos realizar ataques de inyección de objetos PHP y de 'Server-Side Request Forgery' (SSRF) a través de datos serializados manipulados en el parámetro report.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2014-5297",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-10-10T01:55:11.087",
  "references": [
    {
      "url": "http://karmainsecurity.com/KIS-2014-09",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://packetstormsecurity.com/files/128352/X2Engine-4.1.7-PHP-Object-Injection.html",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2014/Sep/77",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/533513/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://x2community.com/topic/1804-important-security-patch/",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://karmainsecurity.com/KIS-2014-09",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://packetstormsecurity.com/files/128352/X2Engine-4.1.7-PHP-Object-Injection.html",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2014/Sep/77",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/533513/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://x2community.com/topic/1804-important-security-patch/",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-94"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The actionSendErrorReport method in protected/controllers/SiteController.php in X2Engine 2.8 through 4.1.7 allows remote attackers to conduct PHP object injection and Server-Side Request Forgery (SSRF) attacks via crafted serialized data in the report parameter."
    },
    {
      "lang": "es",
      "value": "El método actionSendErrorReport en protected/controllers/SiteController.php en X2Engine 2.8 hasta 4.1.7 permite a atacantes remotos realizar ataques de inyección de objetos PHP y de 'Server-Side Request Forgery' (SSRF) a través de datos serializados manipulados en el parámetro report."
    }
  ],
  "lastModified": "2026-06-17T00:11:20.640",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:x2engine:x2engine:2.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0E8129A3-92A9-4D68-B3CB-40AD51E0E1D6"
            },
            {
              "criteria": "cpe:2.3:a:x2engine:x2engine:4.1.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "52E37C2D-0338-45E6-B75D-C79DA56C25A7"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "evaluatorComment": "http://cwe.mitre.org/data/definitions/918.html 'CWE-918: Server-Side Request Forgery (SSRF)'",
  "sourceIdentifier": "cve@mitre.org"
}