7.5
CVSSv2

CVE-2014-7201

Published: 10/10/2014 Updated: 22/10/2014
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in the search function in pi1/class.tx_dmmjobcontrol_pi1.php in the JobControl (dmmjobcontrol) extension 2.14.0 and previous versions for TYPO3 allow remote malicious users to execute arbitrary SQL commands via the (1) education, (2) region, or (3) sector fields, as demonstrated by the tx_dmmjobcontrol_pi1[search][sector][] parameter to jobs/.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kevin renskers dmmjobcontrol

Exploits

Mogwai Security Advisory MSA-2014-02 ---------------------------------------------------------------------- Title: JobControl (dmmjobcontrol) Multiple Vulnerabilities Product: dmmjobcontrol (Typo3 Extension) Affected versions: 2140 Impact: high Remote: yes Product link: typo3org/exten ...