CVE-2014-9145
Last modified
CVE-2014-9145 is a vulnerability of currently unknown severity. Multiple SQL injection vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an edit action to dapur/index.php; (2) cat, (3) user, or (4) level parameter to dapur/apps/app_article/controller/article_list.php; or (5) email parameter in an email action or (6) username parameter in a user action to dapur/apps/app_user/controller/check_user.php.. EPSS estimates a 2.08% chance of exploitation in the next 30 days.
Description
Multiple SQL injection vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an edit action to dapur/index.php; (2) cat, (3) user, or (4) level parameter to dapur/apps/app_article/controller/article_list.php; or (5) email parameter in an email action or (6) username parameter in a user action to dapur/apps/app_user/controller/check_user.php.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fiyo | Fiyo Cms | 2.0.1.8 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-9145?
How severe is CVE-2014-9145?
How do I fix CVE-2014-9145?
Are you affected by CVE-2014-9145?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
