CVE-2014-9464: SQL Injection
Published Jan 3, 2015
·Updated
SQL injection vulnerability in Category.php in Microweber CMS 0.95 before 20141209 allows remote attackers to execute arbitrary SQL commands via the category parameter when displaying a category, related to the $parentid variable.
Affected Software
1 affected component
Microweber Microweber<=0.95
Event History
Jan 3, 2015
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-9464?
CVE-2014-9464 is classified as a medium severity vulnerability due to its potential for SQL injection.
2
How do I fix CVE-2014-9464?
To fix CVE-2014-9464, upgrade Microweber CMS to version 0.95 or later.
3
What systems are affected by CVE-2014-9464?
CVE-2014-9464 affects Microweber CMS versions prior to 20141209.
4
What type of vulnerability is CVE-2014-9464?
CVE-2014-9464 is an SQL injection vulnerability.
5
Can CVE-2014-9464 allow data manipulation?
Yes, CVE-2014-9464 can allow remote attackers to execute arbitrary SQL commands and manipulate the database.