7.5
CVSSv2

CVE-2013-3294

Published: 11/02/2014 Updated: 29/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Exponent CMS prior to 2.2.0 release candidate 1 allow remote malicious users to execute arbitrary SQL commands via the (1) src or (2) username parameter to index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

exponentcms exponent cms 2.1.0

exponentcms exponent cms 2.1.1

exponentcms exponent cms 2.0.0

exponentcms exponent cms 0.99.0

exponentcms exponent cms 2.0.6

exponentcms exponent cms 2.0.7

exponentcms exponent cms 2.1.4

exponentcms exponent cms

exponentcms exponent cms 2.0.3

exponentcms exponent cms 2.0.8

exponentcms exponent cms 2.0.9

exponentcms exponent cms 2.0.2

exponentcms exponent cms 2.0.1

exponentcms exponent cms 2.0.4

exponentcms exponent cms 2.0.5

exponentcms exponent cms 2.1.2

exponentcms exponent cms 2.1.3

exponentcms exponent cms 0.98.0

exponentcms exponent cms 0.97.0

Exploits

Advisory ID: HTB23154 Product: Exponent CMS Vendor: Online Innovative Creations Vulnerable Version(s): 220 beta 3 and probably prior Tested Version: 220 beta 3 Vendor Notification: April 24, 2013 Vendor Patch: May 3, 2013 Public Disclosure: May 15, 2013 Vulnerability Type: SQL Injection [CWE-89], PHP File Inclusion [CWE-98] CVE References: C ...
Exponent CMS version 220 beta 3 suffers from local file inclusion and remote SQL injection vulnerabilities ...