5
CVSSv2

CVE-2014-1631

Published: 31/01/2018 Updated: 26/04/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 510
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Eventum prior to 2.3.5 allows remote malicious users to reinstall the application via direct request to /setup/index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

eventum project eventum

Exploits

source: wwwsecurityfocuscom/bid/65186/info Eventum is prone to an insecure file-permission vulnerability An attacker can exploit this issue to reinstall vulnerable application This may aid in further attacks Eventum 234 is vulnerable; other versions may also be affected Following example URI is available wwwexamplecom ...
Advisory ID: HTB23198 Product: Eventum Vendor: Eventum Development Team Vulnerable Version(s): 234 and probably prior Tested Version: 234 Advisory Publication: January 22, 2014 [without technical details] Vendor Notification: January 22, 2014 Vendor Patch: January 24, 2014 Public Disclosure: January 27, 2014 Vulnerability Type: Incorrect D ...
Eventum version 234 suffers from incorrect default permission and code injection vulnerabilities ...