CVE-2014-1683: Skybluecanvas
Medium severity, CVSS 6.8. EPSS: 31.4% chance of exploitation in the next 30 days.
The bashMail function in cms/data/skins/techjunkie/fragments/contacts/functions.php in SkyBlueCanvas CMS before 1.1 r248-04, when the pid parameter is 4, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) name, (2) email, (3) subject, or (4) message parameter to index.php.
Affected products
- Skybluecanvas Skybluecanvas: up to and including 1.1_r248-03
Published 2014-01-29. Last modified 2026-06-17.