peter bassill · operator
$ cve CVE-2014-3857 JSON

CVE-2014-3857 EXPLOIT

6.5
MEDIUM · CVSS 2.0 · EPSS 2.2% (pctl 82)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in Kerio Control Statistics in Kerio Control (formerly WinRoute Firewall) before 8.3.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) x_16 or (2) x_17 parameter to print.php.

Scoring

CVSS6.5 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS2.17% — more likely to be exploited than 82% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2014-07-03
Last modified2026-06-17

Affected (1)

VendorProduct
keriocontrol

Public exploits

SourceTitleDate
exploit-dbKerio Control 8.3.1 - Blind SQL Injection2014-07-02

References

→ the Explorer  ·  watch your stack  ·  NVD