7.5
CVSSv2

CVE-2014-4170

Published: 13/02/2020 Updated: 19/02/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A Privilege Escalation Vulnerability exists in Free Reprintables ArticleFR 11.06.2014 due to insufficient access restrictions in the data.php script, which could let a remote malicious user obtain access or modify or delete database information.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

freereprintables articlefr

Exploits

Advisory ID: HTB23219 Product: ArticleFR Vendor: Free Reprintables Vulnerable Version(s): 11062014 and probably prior Tested Version: 11062014 Advisory Publication: June 11, 2014 [without technical details] Vendor Notification: June 11, 2014 Public Disclosure: July 30, 2014 Vulnerability Type: Improper Access Control [CWE-284] CVE Reference ...
High-Tech Bridge Security Research Lab discovered vulnerability in ArticleFR, which can be exploited to execute arbitrary UPDATE SQL statements, alter information stored in the database, and gain complete control over the web site ...