AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2014-2279

MEDIUM · CVSS 6.4 EPSS 5.21% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2014-10-17 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

Exhibit — Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

External Security References

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2014-2279
Severity
MEDIUM
CVSS
6.4
EPSS
5.21%

Original Filing — NVD Description

Multiple directory traversal vulnerabilities in SeedDMS (formerly LetoDMS and MyDMS) before 4.3.4 allow (1) remote authenticated users with access to the LogManagement functionality to read arbitrary files via a .. (dot dot) in the logname parameter to out/out.LogManagement.php or (2) remote attackers to write to arbitrary files via a .. (dot dot) in the fileId parameter to op/op.AddFile2.php. NOTE: vector 2 can be leveraged to execute arbitrary code by using CVE-2014-2278.