7.5
CVSSv2

CVE-2014-1945

Published: 09/03/2014 Updated: 10/03/2014
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in ajax_udf.php in OpenDocMan prior to 1.2.7.2 allows remote malicious users to execute arbitrary SQL commands via the add_value parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

opendocman opendocman 1.2.6.3

opendocman opendocman 1.2.6.2

opendocman opendocman 1.2.6.7

opendocman opendocman 1.2.6.6

opendocman opendocman

opendocman opendocman 1.2.7

opendocman opendocman 1.2.6.8

opendocman opendocman 1.2.6.5

Exploits

Advisory ID: HTB23202 Product: OpenDocMan Vendor: Free Document Management Software Vulnerable Version(s): 127 and probably prior Tested Version: 127 Advisory Publication: February 12, 2014 [without technical details] Vendor Notification: February 12, 2014 Vendor Patch: February 24, 2014 Public Disclosure: March 5, 2014 Vulnerability Type: SQL ...
OpenDocMan versions 127 and below suffer from improper access control and remote SQL injection vulnerabilities ...