CVE-2014-5521 Information

Description

plugins/useradmin/fingeruser.php in XRMS CRM possibly 1.99.2 allows remote authenticated users to execute arbitrary code via shell metacharacters in the username parameter.

Reference

http://packetstormsecurity.com/files/128030/XRMS-Blind-SQL-Injection-Command-Execution.html http://seclists.org/fulldisclosure/2014/Aug/78 http://www.exploit-db.com/exploits/34452 http://www.openwall.com/lists/oss-security/2014/08/27/4 http://www.openwall.com/lists/oss-security/2014/08/29/1

Share on: