7.5
CVSSv2

CVE-2014-3872

Published: 27/05/2014 Updated: 26/04/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in the administration login page in D-Link DAP-1350 (Rev. A1) with firmware 1.14 and previous versions allow remote malicious users to execute arbitrary SQL commands via the (1) username or (2) password.

Vulnerable Product Search on Vulmon Subscribe to Product

dlink dap-1350_firmware

dlink dap-1350_firmware 1.10

dlink dap-1350 rev._a1