U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2014-8998

Change History

Initial CVE Analysis 11/20/2014 9:43:11 AM

Action Type Old Value New Value
Added CPE Configuration

								
							
							
						
Configuration 1
     OR
          *cpe:2.3:a:x7chat:x7_chat:2.0.0:*:*:*:*:*:*:*
          *cpe:2.3:a:x7chat:x7_chat:2.0.0:a1:*:*:*:*:*:*
          *cpe:2.3:a:x7chat:x7_chat:2.0.0:a2:*:*:*:*:*:*
          *cpe:2.3:a:x7chat:x7_chat:2.0.0:a3:*:*:*:*:*:*
          *cpe:2.3:a:x7chat:x7_chat:2.0.0:b1:*:*:*:*:*:*
          *cpe:2.3:a:x7chat:x7_chat:2.0.0:b2:*:*:*:*:*:*
          *cpe:2.3:a:x7chat:x7_chat:2.0.1:a1:*:*:*:*:*:*
          *cpe:2.3:a:x7chat:x7_chat:2.0.2:*:*:*:*:*:*:*
          *cpe:2.3:a:x7chat:x7_chat:2.0.3:*:*:*:*:*:*:*
          *cpe:2.3:a:x7chat:x7_chat:2.0.4:*:*:*:*:*:*:*
          *cpe:2.3:a:x7chat:x7_chat:2.0.4.1:*:*:*:*:*:*:*
          *cpe:2.3:a:x7chat:x7_chat:2.0.4.3:*:*:*:*:*:*:*
          *cpe:2.3:a:x7chat:x7_chat:2.0.4.4:*:*:*:*:*:*:*
          *cpe:2.3:a:x7chat:x7_chat:2.0.5:*:*:*:*:*:*:*
          *cpe:2.3:a:x7chat:x7_chat:2.0.5.1:*:*:*:*:*:*:*
Added CVSS V2

								
							
							
						
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
Added CWE

								
							
							
						
CWE-94
Changed Reference Type
http://packetstormsecurity.com/files/128964/X7-Chat-2.0.5-lib-message.php-preg_replace-PHP-Code-Execution.html No Types Assigned
http://packetstormsecurity.com/files/128964/X7-Chat-2.0.5-lib-message.php-preg_replace-PHP-Code-Execution.html Exploit
Changed Reference Type
http://www.exploit-db.com/exploits/35183 No Types Assigned
http://www.exploit-db.com/exploits/35183 Exploit