6.5
CVSSv2

CVE-2014-5387

Published: 04/11/2014 Updated: 06/07/2020
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in EllisLab ExpressionEngine prior to 2.9.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) column_filter or (2) category[] parameter to system/index.php or the (3) tbl_sort[0][] parameter in the comment module to system/index.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ellislab expressionengine 2..5.4

expressionengine expressionengine 2.5.3

expressionengine expressionengine 2.5.2

expressionengine expressionengine 2.5.1

expressionengine expressionengine 2.5.0

ellislab expressionengine 2.0.2

ellislab expressionengine 2.0.1

ellislab expressionengine 2.0.0

expressionengine expressionengine 2.8.0

expressionengine expressionengine 2.7.3

ellislab expressionengine 2.7.2

ellislab expressionengine 2.7.1

expressionengine expressionengine 2.2.1

expressionengine expressionengine 2.2.0

expressionengine expressionengine 2.1.5

expressionengine expressionengine 2.1.4

expressionengine expressionengine

ellislab expressionengine 2.6.1

ellislab expressionengine 2.5.5

ellislab expressionengine 2.3.1

expressionengine expressionengine 2.2.2

expressionengine expressionengine 2.1.3

expressionengine expressionengine 2.1.1

ellislab expressionengine 2.8.1

expressionengine expressionengine 2.7.0

expressionengine expressionengine 2.6.0

expressionengine expressionengine 2.4.0

expressionengine expressionengine 2.3.0

expressionengine expressionengine 2.1.2

expressionengine expressionengine 2.1.0

Exploits

EllisLab ExpressionEngine Core versions prior to 290 suffer from multiple authenticated remote SQL injection vulnerabilities ...