6.8
CVSSv2

CVE-2014-2317

Published: 09/03/2014 Updated: 10/03/2014
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in ajax_udf.php in OpenDocMan prior to 1.2.7.2 allows remote malicious users to execute arbitrary SQL commands via the table parameter. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

opendocman opendocman 1.2.6.2

opendocman opendocman 1.2.7

opendocman opendocman 1.2.6.3

opendocman opendocman 1.2.6.7

opendocman opendocman 1.2.6.6

opendocman opendocman 1.2.6.5

opendocman opendocman

opendocman opendocman 1.2.6.8

Exploits

Advisory ID: HTB23202 Product: OpenDocMan Vendor: Free Document Management Software Vulnerable Version(s): 127 and probably prior Tested Version: 127 Advisory Publication: February 12, 2014 [without technical details] Vendor Notification: February 12, 2014 Vendor Patch: February 24, 2014 Public Disclosure: March 5, 2014 Vulnerability Type: SQL ...