7.5
CVSSv2

CVE-2014-2303

Published: 13/06/2014 Updated: 09/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in the file browser component (we_fs.php) in webEdition CMS prior to 6.2.7-s1.2 and 6.3.x up to and including 6.3.8 before -s1 allow remote malicious users to execute arbitrary SQL commands via the (1) table or (2) order parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

webedition webedition cms 6.3.8.0

webedition webedition cms 6.3.3.0

webedition webedition cms 6.2.7.0

Exploits

source: wwwsecurityfocuscom/bid/67689/info webEdition CMS is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input A successful exploit will allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database webEd ...
RedTeam Pentesting discovered an SQL injection vulnerability in the file browser component of webEdition CMS during a penetration test Unauthenticated attackers can get read-only access on the SQL database used by webEdition and read for example password hashes used by administrative accounts webEdition versions 6380 svn6985 down to 6330 is ...