Vulnerability Details CVE-2014-1216
FitNesse Wiki 20131110, 20140201, and earlier allows remote attackers to execute arbitrary commands by defining a COMMAND_PATTERN and TEST_RUNNER in the pageContent parameter when editing a page.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.07
EPSS Ranking 91.2%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2014-1216
-
cpe:2.3:a:fitnesse:fitnesse_wiki:20131110
-
cpe:2.3:a:fitnesse:fitnesse_wiki:20140201