Vulnerabilities > CVE-2014-1216 - Remote Code Execution vulnerability in Fitnesse

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
fitnesse
exploit available

Summary

FitNesse Wiki 20131110, 20140201, and earlier allows remote attackers to execute arbitrary commands by defining a COMMAND_PATTERN and TEST_RUNNER in the pageContent parameter when editing a page. Per: https://cwe.mitre.org/data/definitions/77.html "CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')"

Vulnerable Configurations

Part Description Count
Application
Fitnesse
2

Exploit-Db

descriptionFitnesse Wiki - Remote Command Execution Vulnerability. CVE-2014-1216. Remote exploit for windows platform
fileexploits/windows/remote/32568.rb
idEDB-ID:32568
last seen2016-02-03
modified2014-03-28
platformwindows
port80
published2014-03-28
reporterSecPod Research
sourcehttps://www.exploit-db.com/download/32568/
titleFitnesse Wiki - Remote Command Execution Vulnerability
typeremote

Packetstorm

Seebug

  • bulletinFamilyexploit
    descriptionBugtraq ID:65921 CVE ID:CVE-2014-1216 FitNesse是一套软件开发协作工具。 Fitnesse Wiki不正确校验已编辑页面语法参数数据,允许远程攻击者利用漏洞提交特殊的请求以应用程序上下文执行任意命令。 0 Fitnesse Wiki v20131110 目前没有详细解决方案提供: http://www.fitnesse.org
    idSSV:61648
    last seen2017-11-19
    modified2014-03-05
    published2014-03-05
    reporterRoot
    sourcehttps://www.seebug.org/vuldb/ssvid-61648
    titleFitnesse远程代码执行漏洞
  • bulletinFamilyexploit
    descriptionNo description provided by source.
    idSSV:85849
    last seen2017-11-19
    modified2014-07-01
    published2014-07-01
    reporterRoot
    sourcehttps://www.seebug.org/vuldb/ssvid-85849
    titleFitnesse Wiki Remote Command Execution Vulnerability