7.5
CVSSv2

CVE-2015-1467

Published: 06/02/2015 Updated: 09/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Translations in Fork CMS prior to 3.8.6 allow remote authenticated users to execute arbitrary SQL commands via the (1) language[] or (2) type[] parameter to private/en/locale/index.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fork-cms fork cms

Exploits

[CVE-2015-1467] Fork CMS - SQL Injection in Version 385 ---------------------------------------------------------------- Product Information: Software: Fork CMS Tested Version: 385, released on Wednesday 14 January 2015 Vulnerability Type: SQL Injection (CWE-89) Download link to tested version: wwwfork-cmscom/download?release=38 ...
Fork CMS version 385 suffers from a remote SQL injection vulnerability ...