VDB
CVE-2014-2935
CVE-2014-2935
PUBLISHED
CVSS 10 CRITICAL
costview3/xmlrpc_server/xmlrpc.php in CostView in Caldera 9.20 allows remote attackers to execute arbitrary commands via shell metacharacters in a methodCall element in a PHP XMLRPC request.
EPSS 1.53% · 81.7th percentile
Risk Scores
CVSS 2.0
10
EPSS Score
1.53%
81.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| caldera | caldera | 9.20 |
Timeline
- May 8, 2014 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 3, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 8, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 16, 2023 EPSS Score
- Sep 7, 2023 EPSS Score
References
- 67252 vdb
- VU#693092 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2014-2935 advisory