7.5
CVSSv2

CVE-2014-9148

Published: 16/10/2017 Updated: 25/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Fiyo CMS 2.0.1.8 allows remote malicious users to bypass intended access restrictions and execute the (1) "Install and Update" or (2) Backup super administrator function via the view parameter in a direct request to fiyo/dapur.

Vulnerable Product Search on Vulmon Subscribe to Product

fiyo fiyo cms

Exploits

# Exploit Title: FiyoCMS Multiple Vulnerabilities # Date: 29 March 2015 # Exploit Author: Mahendra # Vendor Homepage: wwwfiyoorg # Software Link: sourceforgenet/projects/fiyo-cms/ # Version: 2018, other version might be vulnerable # Tested : Kali Linux 109a-amd64 # CVE(s): CVE-2014-9145,CVE-2014-9146,CVE-2014-9147,CVE-2014-9148 *Ad ...
FiyoCMS version 2018 suffers from url bypass, cross site scripting, and remote SQL injection vulnerabilities ...