← Back

CVE-2014-6633

nvd nist
Published: Apr 12, 2018Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

The safe_eval function in trytond in Tryton before 2.4.15, 2.6.x before 2.6.14, 2.8.x before 2.8.11, 3.0.x before 3.0.7, and 3.2.x before 3.2.3 allows remote authenticated users to execute arbitrary commands via shell metacharacters in (1) the collection.domain in the webdav module or (2) the formula field in the price_list module.

Affected (5)

Products: Tryton: Tryton
1 product
Tryton
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Tryton
From 2.4.0 to 2.4.15
From 2.6.0 to 2.6.14
From 2.8.0 to 2.8.11
From 3.0.0 to 3.0.7
From 3.2.0 to 3.2.3

References (4)

Source: cve@mitre.org
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking

Timeline

No history available yet.