PT-2024-10557 · Unknown · Actual Analyzer

Benjamin Harris

+1

·

Published

2024-06-21

·

Updated

2024-07-03

·

CVE-2014-5470

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Actual Analyzer versions prior to 2014-08-29
Description The issue allows code execution via shell metacharacters because untrusted input is used for part of the input data passed to an eval operation.
Recommendations For versions prior to 2014-08-29, at the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2014-5470

Affected Products

Actual Analyzer