First published: Sat Jan 03 2015(Updated: )
SQL injection vulnerability in Category.php in Microweber CMS 0.95 before 20141209 allows remote attackers to execute arbitrary SQL commands via the category parameter when displaying a category, related to the $parent_id variable.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microweber WHMCS | <=0.95 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-9464 is classified as a medium severity vulnerability due to its potential for SQL injection.
To fix CVE-2014-9464, upgrade Microweber CMS to version 0.95 or later.
CVE-2014-9464 affects Microweber CMS versions prior to 20141209.
CVE-2014-9464 is an SQL injection vulnerability.
Yes, CVE-2014-9464 can allow remote attackers to execute arbitrary SQL commands and manipulate the database.