6.5
CVSSv2

CVE-2014-6045

Published: 28/08/2018 Updated: 31/10/2018
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in phpMyFAQ prior to 2.8.13 allows remote authenticated users with certain permissions to execute arbitrary SQL commands via vectors involving the restore function.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyfaq phpmyfaq

Exploits

#Title: phpMyFAQ 28X - Multiple Vulnerabilities #Vendor: phpmyfaqde #Date: 040919 #Version: >= 2812 (Latest ATM) #Tested on: Apache 22 / PHP 54 / Linux #Contact: smash [at] devilteampl 1) Persistent XSS Administrator is able to view information about specific user session in 'Statistic' tab Over there, you may find informations ...