Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-9445

Опубликовано: 02 янв. 2015
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

SQL injection vulnerability in incl/create.inc.php in Installatron GQ File Manager 0.2.5 allows remote attackers to execute arbitrary SQL commands via the create parameter to index.php. NOTE: this can be leveraged for cross-site scripting (XSS) attacks by creating a file that generates an error. NOTE: this issue was originally incorrectly mapped to CVE-2014-1137; see CVE-2014-1137 for more information.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:installatron:gatequest_file_manager:0.2.5:*:*:*:*:*:*:*

EPSS

Процентиль: 49%
0.00258
Низкий

7.5 High

CVSS2

Дефекты

CWE-89

Связанные уязвимости

github
больше 3 лет назад

SQL injection vulnerability in incl/create.inc.php in Installatron GQ File Manager 0.2.5 allows remote attackers to execute arbitrary SQL commands via the create parameter to index.php. NOTE: this can be leveraged for cross-site scripting (XSS) attacks by creating a file that generates an error. NOTE: this issue was originally incorrectly mapped to CVE-2014-1137; see CVE-2014-1137 for more information.

EPSS

Процентиль: 49%
0.00258
Низкий

7.5 High

CVSS2

Дефекты

CWE-89