← Back

CVE-2014-8998

nvd nist
Published: Nov 20, 2014Modified: May 6, 2026

JSON object

Loading...
6.5
Vector
AV:N/AC:L/Au:S/C:P/I:P/A:P
Exploitability: 8.0 / Impact: 6.4
Source: NVD

Description

lib/message.php in X7 Chat 2.0.0 through 2.0.5.1 allows remote authenticated users to execute arbitrary PHP code via a crafted HTTP header to index.php, which is processed by the preg_replace function with the eval switch.

Affected (15)

Products: X7chat: X7 Chat
1 product
X7 Chat
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
X7chat
Version 2.0.0
Version 2.0.0 a1
Version 2.0.0 a2
Version 2.0.0 a3
Version 2.0.0 b1
Version 2.0.0 b2
Version 2.0.1 a1
Version 2.0.2
Version 2.0.3
Version 2.0.4.1
Version 2.0.4.3
Version 2.0.4.4
Version 2.0.4
Version 2.0.5.1
Version 2.0.5

Timeline

No history available yet.