peter bassill · operator
$ cve CVE-2014-8596 JSON

CVE-2014-8596 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 3.3% (pctl 88)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in PHP-Fusion 7.02.07 allow remote authenticated users to execute arbitrary SQL commands via the (1) submit_id parameter in a 2 action to files/administration/submissions.php or (2) status parameter to files/administration/members.php.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS3.26% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2014-11-17
Last modified2026-06-17

Affected (1)

VendorProduct
php-fusionphp-fusion

Public exploits

SourceTitleDate
exploit-dbPHP-Fusion 7.02.07 - SQL Injection2014-11-10

References

→ the Explorer  ·  watch your stack  ·  NVD