7.1
CVSSv2

CVE-2014-2022

Published: 15/10/2014 Updated: 13/08/2015
CVSS v2 Base Score: 7.1 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 715
Vector: AV:N/AC:H/Au:S/C:C/I:C/A:C

Vulnerability Summary

SQL injection vulnerability in includes/api/4/breadcrumbs_create.php in vBulletin 4.2.2, 4.2.1, 4.2.0 PL2, and previous versions allows remote authenticated users to execute arbitrary SQL commands via the conceptid argument in an xmlrpc API request.

Vulnerable Product Search on Vulmon Subscribe to Product

vbulletin vbulletin

vbulletin vbulletin 4.2.1

vbulletin vbulletin 4.2.0

Exploits

CVE-2014-2022 - vbulletin 4x - SQLi in breadcrumbs via xmlrpc API (post-auth) ============================================================================== Overview -------- date : 10/12/2014 cvss : 71 (AV:N/AC:H/Au:S/C:C/I:C/A:C) base cwe : 89 vendor : vBulletin Solutions product : vBulletin 4 versions affected : ...
vBulletin version 4x suffers from a remote SQL injection vulnerability via the xmlrpc API ...