7.5
CVSSv2

CVE-2014-9464

Published: 03/01/2015 Updated: 05/01/2015
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in Category.php in Microweber CMS 0.95 prior to 20141209 allows remote malicious users to execute arbitrary SQL commands via the category parameter when displaying a category, related to the $parent_id variable.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microweber microweber

Exploits

# Exploit Title: SQL Injection in Microweber CMS 095 # Google Dork: N/A # Date: 12/16/2014 # Exploit Author: Pham Kien Cuong (cuongkpham@itasvn) and ITAS Team (wwwitasvn) # Vendor Homepage: Microweber (microwebercom/) # Software Link: githubcom/microweber/microweber # Version: 095 # Tested on: N/A # CVE : CVE-2014-9464 ::P ...
Microweber CMS version 095 suffers from a remote SQL injection vulnerability ...