CVE-2014-1401: SQL Injection
Multiple SQL injection vulnerabilities in AuraCMS 2.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) search parameter to mod/content/content.php or (2) CLIENTIP, (3) XFORWARDEDFOR, (4) XFORWARDED, (5) FORWARDEDFOR, or (6) FORWARDED HTTP header to index.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1401?
The severity of CVE-2014-1401 is considered to be high due to its ability to allow remote authenticated users to execute arbitrary SQL commands.
How do I fix CVE-2014-1401?
To fix CVE-2014-1401, upgrade your AuraCMS to version 2.4 or later to mitigate the SQL injection vulnerabilities.
Who is affected by CVE-2014-1401?
CVE-2014-1401 affects AuraCMS versions 2.3 and earlier, including multiple earlier versions like 1.0 to 2.2.2.
What types of SQL injection are present in CVE-2014-1401?
CVE-2014-1401 includes multiple SQL injection vulnerabilities through parameters such as 'search' and various HTTP headers.
Can CVE-2014-1401 be exploited remotely?
Yes, CVE-2014-1401 can be exploited remotely by authenticated users, allowing unauthorized SQL command execution.