Vulnerability Description
Static code injection vulnerability in install.php in Morfy CMS 1.05 allows remote authenticated users to inject arbitrary PHP code into config.php via the site_url parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Morfy Cms Project | Morfy Cms | <= 1.04 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/129624/Morfy-CMS-1.05-Remote-Command-ExecutExploit
- http://seclists.org/fulldisclosure/2014/Dec/70Exploit
- http://www.securityfocus.com/archive/1/534271/100/0/threaded
- http://www.vulnerability-lab.com/get_content.php?id=1367Exploit
- https://github.com/Awilum/monstra-cms/issues/351
- http://packetstormsecurity.com/files/129624/Morfy-CMS-1.05-Remote-Command-ExecutExploit
- http://seclists.org/fulldisclosure/2014/Dec/70Exploit
- http://www.securityfocus.com/archive/1/534271/100/0/threaded
- http://www.vulnerability-lab.com/get_content.php?id=1367Exploit
- https://github.com/Awilum/monstra-cms/issues/351
FAQ
What is CVE-2014-9185?
CVE-2014-9185 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Static code injection vulnerability in install.php in Morfy CMS 1.05 allows remote authenticated users to inject arbitrary PHP code into config.php via the site_url parameter.
How severe is CVE-2014-9185?
CVE-2014-9185 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-9185?
Check the references section above for vendor advisories and patch information. Affected products include: Morfy Cms Project Morfy Cms.