CVE-2014-7178: Enalean Tuleap
High severity, CVSS 9.3. EPSS: 5.1% chance of exploitation in the next 30 days.
Enalean Tuleap before 7.5.99.6 allows remote attackers to execute arbitrary commands via the User-Agent header, which is provided to the passthru PHP function.
Affected products
- Enalean Tuleap: up to and including 7.5.99.5
Published 2014-11-28. Last modified 2026-06-17.