7.5
CVSSv2

CVE-2014-9095

Published: 26/11/2014 Updated: 08/11/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Raritan Power IQ 4.1.0 and 4.2.1 allow remote malicious users to execute arbitrary SQL commands via the (1) sort or (2) dir parameter to license/records.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

raritan power iq 4.1.0

raritan power iq 4.2.1

Exploits

=begin Raritan PowerIQ suffers from an unauthenticated SQL injection vulnerability within an endpoint used during initial configuration of the licensing for the product This endpoint is still available after the appliance has been fully configured POST /license/records HTTP/11 Host: 192168111 User-Agent: Mozilla/50 (Macintosh; Intel Mac O ...