Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2014-9113

EPSS 1.52% · P81
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2014-9113

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
CCH Wolters Kluwer ProSystem fx Engagement (aka PFX Engagement) 7.1 and earlier uses weak permissions (Authenticated Users: Modify and Write) for the (1) Pfx.Engagement.WcfServices, (2) PFXEngDesktopService, (3) PFXSYNPFTService, and (4) P2EWinService service files in PFX Engagement\, which allows local users to obtain LocalSystem privileges via a Trojan horse file.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
CCH Wolters Kluwer PFX Engagement 权限许可和访问控制漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
CCH Wolters Kluwer ProSystem fx Engagement(又名PFX Engagement)是荷兰CCH Wolters Kluwer公司的一套会计与审计管理工具。该工具支持创建财务报表、导出报税表、审查税务数据等。 CCH Wolters Kluwer ProSystem fx Engagement 7.1及之前版本中存在安全漏洞,该漏洞源于程序为PFX Engagement\ URI中的Pfx.Engagement.WcfServices、 PFXEngDesktopSer
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2014-9113

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2014-9113

Please Login to view more intelligence information

Same Patch Batch · n/a · 2014-12-02 · 26 CVEs total

CVE-2014-9175WordPress wpDataTables插件SQL注入漏洞
CVE-2014-8791Enalean Tuleap‘unserialize()’函数代码注入漏洞
CVE-2014-5284OSSEC 不安全临时文件创建漏洞
CVE-2014-3703OpenStack PackStack 安全漏洞
CVE-2014-3068IBM Java Runtime Environment 安全漏洞
CVE-2014-3065IBM Java Runtime Environment 输入验证漏洞
CVE-2013-6494Fedora FedUp 不安全临时文件创建漏洞
CVE-2014-9181Plex Media Server 目录遍历漏洞
CVE-2014-9180Eleanor CMS 代码注入漏洞
CVE-2014-9179WordPress SupportEzzy Ticket System插件跨站脚本漏洞
CVE-2014-9178WordPress Smarty Pants Plugins SP Project & Document Manager插件SQL注入漏洞
CVE-2014-9177WordPress HTML5 MP3 Player with Playlist Free插件信息泄露漏洞
CVE-2014-9176WordPress InstaSqueeze Sexy Squeeze Pages插件跨站脚本漏洞
CVE-2014-9182Anchor CMS‘comment.php’跨站脚本漏洞
CVE-2014-9174WordPress Google Analytics by Yoast插件跨站脚本漏洞
CVE-2014-9173WordPress Google Doc Embedder插件SQL注入漏洞
CVE-2014-9116Mutt ‘write_one_header’和‘mutt_substrdup()’函数基于堆的缓冲区溢出漏洞
CVE-2014-9112GNU Cpio‘list_file()’基于堆的缓冲区溢出漏洞
CVE-2014-8874TYPO3 ke_questionnaire扩展信息泄露漏洞
CVE-2014-8789Gleamtech FileVista 输入验证漏洞

Showing top 20 of 26 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2014-9113

No comments yet


Leave a comment