Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2014-9567

EPSS 82.89% · P99
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2014-9567

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Unrestricted file upload vulnerability in process-upload.php in ProjectSend (formerly cFTP) r100 through r561 allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in the upload/files/ or upload/temp/ directory.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
ProjectSend 代码注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
ProjectSend(前称cFTP)是一套基于PHP和MySQL的自托管应用程序。 ProjectSend r100版本至r561版本的process-upload.php脚本中存在任意文件上传漏洞。远程攻击者可通过发送直接的请求,上传并访问带有PHP扩展的文件利用该漏洞执行任意PHP代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2014-9567

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2014-9567

Please Login to view more intelligence information

Same Patch Batch · n/a · 2015-01-07 · 13 CVEs total

CVE-2014-4635EMC Documentum Web Development Kit 跨站脚本漏洞
CVE-2014-4636EMC Documentum Web Development Kit 跨站请求伪造漏洞
CVE-2014-4637EMC Documentum Web Development Kit 开放重定向漏洞
CVE-2014-4638EMC Documentum Web Development Kit 信息泄露漏洞
CVE-2014-4639EMC Documentum Web Development Kit 数字错误漏洞
CVE-2014-3779ZOHO ManageEngine ADSelfService Plus 跨站脚本漏洞
CVE-2014-8993Open-Xchange AppSuite 跨站脚本漏洞
CVE-2014-1425cmanager 信息泄露漏洞
CVE-2014-9221strongSwan 拒绝服务漏洞
CVE-2014-9493OpenStack Image Registry and Delivery Service 权限许可和访问控制漏洞
CVE-2014-9569SAP NetWeaver Business Client for HTML 跨站脚本漏洞
CVE-2015-0361Xen 资源管理错误漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2014-9567

No comments yet


Leave a comment