CVE-2009-3514
Last modified
CVE-2009-3514 is a vulnerability of currently unknown severity. Multiple SQL injection vulnerabilities in d.net CMS allow remote attackers to execute arbitrary SQL commands via (1) the page parameter to index.php; and allow remote authenticated administrators to execute arbitrary SQL commands via the (2) edit_id and (3) _p parameter in a news action to dnet_admin/index.php.. EPSS estimates a 0.84% chance of exploitation in the next 30 days.
Description
Multiple SQL injection vulnerabilities in d.net CMS allow remote attackers to execute arbitrary SQL commands via (1) the page parameter to index.php; and allow remote authenticated administrators to execute arbitrary SQL commands via the (2) edit_id and (3) _p parameter in a news action to dnet_admin/index.php.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Marcin Manek | D.Net Cms | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-3514?
How severe is CVE-2009-3514?
How do I fix CVE-2009-3514?
Are you affected by CVE-2009-3514?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
