← Back

CVE-2014-1999

nvd nist
Published: Jul 20, 2014Modified: May 6, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

The auto-format feature in the Request_Curl class in FuelPHP 1.1 through 1.7.1 allows remote attackers to execute arbitrary code via a crafted response.

Affected (14)

Products: Fuelphp: Fuelphp
1 product
Fuelphp
Configuration A
14 vulnerable
Vulnerable SoftwareAffected Versions
Fuelphp
Version 1.1
Version 1.2.1
Version 1.2
Version 1.2 rc1
Version 1.3
Version 1.4
Version 1.5.1
Version 1.5.2
Version 1.5.3
Version 1.5
Version 1.6.1
Version 1.6
Version 1.7.1
Version 1.7

References (6)

Source: vultures@jpcert.or.jp
Vendor Advisory
Source: vultures@jpcert.or.jp
Vendor Advisory
Source: vultures@jpcert.or.jp
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.