CVE-2014-9567

Exp

Unrestricted file upload vulnerability in process-upload.php in ProjectSend (formerly cFTP) r100 through r561 allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in the upload/files/ or upload/temp/ directory.

Published: 2015-01-07 Last update: 2026-05-06 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2014-9567 is rated High Exploit Risk (84.7/100): CVSS High severity, with high exploitation likelihood (EPSS 82.89%, 99th percentile). Core evidence: 5 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +74.00% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2014-9567

EDB-ID Source Kind Published Link
35660 exploit_db edb 2014-12-31 Exploit-DB ↗
35424 exploit_db edb 2014-12-02 Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2014-9567

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-10-08 8.89% 82.89% +74.00%
2 2025-09-22 8.22% 8.89% +0.67%
3 2025-04-11 8.22%

Full EPSS history (12 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2014-9567

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
7.5 2.0 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:P)
Partial availability impact.
10.0 6.4 [email protected]

Weakness enumeration for CVE-2014-9567

Affected software / configurations for CVE-2014-9567

Vendor Product Version Raw CPE
projectsend projectsend 100 cpe:2.3:a:projectsend:projectsend:100:*:*:*:*:*:*:*
projectsend projectsend 102 cpe:2.3:a:projectsend:projectsend:102:*:*:*:*:*:*:*
projectsend projectsend 105 cpe:2.3:a:projectsend:projectsend:105:*:*:*:*:*:*:*
projectsend projectsend 110 cpe:2.3:a:projectsend:projectsend:110:*:*:*:*:*:*:*
projectsend projectsend 155 cpe:2.3:a:projectsend:projectsend:155:*:*:*:*:*:*:*
projectsend projectsend 156 cpe:2.3:a:projectsend:projectsend:156:*:*:*:*:*:*:*
projectsend projectsend 157 cpe:2.3:a:projectsend:projectsend:157:*:*:*:*:*:*:*
projectsend projectsend 161 cpe:2.3:a:projectsend:projectsend:161:*:*:*:*:*:*:*
projectsend projectsend 180 cpe:2.3:a:projectsend:projectsend:180:*:*:*:*:*:*:*
projectsend projectsend 335 cpe:2.3:a:projectsend:projectsend:335:*:*:*:*:*:*:*
projectsend projectsend 375 cpe:2.3:a:projectsend:projectsend:375:*:*:*:*:*:*:*
projectsend projectsend 405 cpe:2.3:a:projectsend:projectsend:405:*:*:*:*:*:*:*
projectsend projectsend 412 cpe:2.3:a:projectsend:projectsend:412:*:*:*:*:*:*:*
projectsend projectsend 514 cpe:2.3:a:projectsend:projectsend:514:*:*:*:*:*:*:*
projectsend projectsend 561 cpe:2.3:a:projectsend:projectsend:561:*:*:*:*:*:*:*

References for CVE-2014-9567

cvelogic Threat Intelligence