6.5
CVSSv2

CVE-2014-1401

Published: 11/02/2014 Updated: 09/10/2018
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in AuraCMS 2.3 and previous versions allow remote authenticated users to execute arbitrary SQL commands via the (1) search parameter to mod/content/content.php or (2) CLIENT_IP, (3) X_FORWARDED_FOR, (4) X_FORWARDED, (5) FORWARDED_FOR, or (6) FORWARDED HTTP header to index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

auracms auracms 2.2.2

auracms auracms 1.5

auracms auracms 2.1

auracms auracms 2.2

auracms auracms 2.2.1

auracms auracms 1.62

auracms auracms 2.0

auracms auracms 1.1

auracms auracms 1.0

auracms auracms

auracms auracms 1.61

auracms auracms 1.3

auracms auracms 1.2

Exploits

Advisory ID: HTB23196 Product: AuraCMS Vendor: AuraCMS Vulnerable Version(s): 23 and probably prior Tested Version: 23 Advisory Publication: January 8, 2014 [without technical details] Vendor Notification: January 8, 2014 Vendor Patch: January 30, 2014 Public Disclosure: February 5, 2014 Vulnerability Type: SQL Injection [CWE-89] CVE Referen ...
AuraCMS version 23 suffers from a remote SQL injection vulnerability ...