7.5
CVSSv2

CVE-2014-3757

Published: 15/05/2014 Updated: 21/10/2015
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in sorter.php in the phpManufaktur kitForm extension 0.43 and previous versions for the KeepInTouch (KIT) module allows remote malicious users to execute arbitrary SQL commands via the sorter_value parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmanufaktur kitform

phpmanufaktur kitform 0.38

phpmanufaktur kitform 0.36

phpmanufaktur kitform 0.29

phpmanufaktur kitform 0.27

phpmanufaktur kitform 0.20

phpmanufaktur kitform 0.42

phpmanufaktur kitform 0.41

phpmanufaktur kitform 0.40

phpmanufaktur kitform 0.39

phpmanufaktur kitform 0.25

phpmanufaktur kitform 0.24

phpmanufaktur kitform 0.23

phpmanufaktur kitform 0.22

phpmanufaktur kitform 0.18

phpmanufaktur kitform 0.13

phpmanufaktur kitform 0.11

phpmanufaktur kitform 0.34

phpmanufaktur kitform 0.33

phpmanufaktur kitform 0.32

phpmanufaktur kitform 0.31

phpmanufaktur kitform 0.30

phpmanufaktur kitform 0.17

phpmanufaktur kitform 0.16

phpmanufaktur kitform 0.15

phpmanufaktur kitform 0.14

phpmanufaktur kitform 0.37

phpmanufaktur kitform 0.35

phpmanufaktur kitform 0.28

phpmanufaktur kitform 0.26

phpmanufaktur kitform 0.21

phpmanufaktur kitform 0.19

phpmanufaktur kitform 0.12

phpmanufaktur kitform 0.10

Exploits

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Happy easter * Product: phpManufaktur / kitForm * Version: <= 043 (2013-11-22) * Date: 2014-04-20 * Criticality: Medium * Exploitable from: Remote * Impact: SQL Injection * Product URL: githubcom/phpManufaktur/kitForm 1 Vendor Description: kitForm is an extension for the Customer Rel ...