7.5
CVSSv2

CVE-2013-7139

Published: 09/01/2014 Updated: 10/01/2014
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in download.php in Horizon Quick Content Management System (QCMS) 4.0 and previous versions allows remote to execute arbitrary SQL commands via the category parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

cynthia fridsma horizon quick content management system

cynthia fridsma horizon quick content management system 3.2

cynthia fridsma horizon quick content management system 3.5.1

cynthia fridsma horizon quick content management system 3.3

cynthia fridsma horizon quick content management system 3.5.2

cynthia fridsma horizon quick content management system 3.4

Exploits

Advisory ID: HTB23191 Product: Horizon QCMS Vendor: Horizon QCMS Vulnerable Version(s): 40 and probably prior Tested Version: 40 Advisory Publication: December 18, 2013 [without technical details] Vendor Notification: December 18, 2013 Vendor Patch: December 25, 2013 Public Disclosure: January 8, 2014 Vulnerability Type: Path Traversal [CWE- ...
Horizon QCMS version 40 suffers from remote SQL injection and directory traversal vulnerabilities ...