CVE-2014-9096: SQL Injection
Published Nov 26, 2014
·Updated
Multiple SQL injection vulnerabilities in recover.php in Pligg CMS 2.0.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) n parameter.
Affected Software
1 affected component
Pligg Pligg CMS<=2.0.1
Event History
Nov 26, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-9096?
CVE-2014-9096 is classified as a high-severity SQL injection vulnerability.
2
How can I fix CVE-2014-9096?
To fix CVE-2014-9096, upgrade Pligg CMS to version 2.0.2 or later.
3
What are the attack vectors for CVE-2014-9096?
Attackers exploit CVE-2014-9096 through the 'id' or 'n' parameters in recover.php.
4
Who is affected by CVE-2014-9096?
CVE-2014-9096 affects Pligg CMS versions 2.0.1 and earlier.
5
What type of vulnerability is CVE-2014-9096?
CVE-2014-9096 is an SQL injection vulnerability that allows arbitrary SQL command execution.