{"id":"GHSA-mpx3-mx2p-9gv3","summary":"Improper Neutralization of Special Elements used in a Command in FitNesse Wiki","details":"FitNesse Wiki 20131110, 20140201, and earlier allows remote attackers to execute arbitrary commands by defining a COMMAND_PATTERN and TEST_RUNNER in the pageContent parameter when editing a page.","aliases":["CVE-2014-1216"],"modified":"2024-12-07T05:40:12.854356Z","published":"2022-05-17T04:46:05Z","database_specific":{"github_reviewed_at":"2022-07-07T22:51:10Z","nvd_published_at":"2014-04-22T13:06:00Z","cwe_ids":["CWE-77"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-1216"},{"type":"WEB","url":"http://www.exploit-db.com/exploits/32568"}],"affected":[{"package":{"name":"org.fitnesse:fitnesse","ecosystem":"Maven","purl":"pkg:maven/org.fitnesse/fitnesse"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"20131110"},{"fixed":"20140418"}]}],"versions":["20131110","20140201"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-mpx3-mx2p-9gv3/GHSA-mpx3-mx2p-9gv3.json"}}],"schema_version":"1.9.0"}