{ "schema_version": "1.4.0", "id": "GHSA-hr85-6c3j-3cpx", "modified": "2025-04-12T12:42:21Z", "published": "2022-05-17T04:19:34Z", "aliases": [ "CVE-2014-7178" ], "details": "Enalean Tuleap before 7.5.99.6 allows remote attackers to execute arbitrary commands via the User-Agent header, which is provided to the passthru PHP function.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-7178" }, { "type": "WEB", "url": "https://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-7178" }, { "type": "WEB", "url": "https://www.tuleap.org/recent-vulnerabilities" }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2014/Oct/121" } ], "database_specific": { "cwe_ids": [ "CWE-20" ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2014-11-28T15:59:00Z" } }