Zikula Application Framework before 1.3.7 build 11 allows remote attackers to conduct PHP object injection attacks and delete arbitrary files or execute arbitrary PHP code via crafted serialized data in the (1) authentication_method_ser or (2) authentication_info_ser parameter to index.php, or (3) zikulaMobileTheme parameter to index.php.
                
            Metrics
Affected Vendors & Products
References
        History
                    No history.
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: mitre
Published: 2018-03-26T18:00:00
Updated: 2024-08-06T10:06:00.304Z
Reserved: 2014-03-06T00:00:00
Link: CVE-2014-2293
 Vulnrichment
                        Vulnrichment
                    No data.
 NVD
                        NVD
                    Status : Modified
Published: 2018-03-26T18:29:00.300
Modified: 2024-11-21T02:06:01.250
Link: CVE-2014-2293
 Redhat
                        Redhat
                    No data.