peter bassill · operator
$ cve CVE-2014-9095 JSON

CVE-2014-9095 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.3% (pctl 83)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in Raritan Power IQ 4.1.0 and 4.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) sort or (2) dir parameter to license/records.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.35% — more likely to be exploited than 83% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2014-11-26
Last modified2026-06-17

Affected (1)

VendorProduct
raritanpower iq

Public exploits

SourceTitleDate
exploit-dbRaritan PowerIQ 4.1.0 - SQL Injection (Metasploit)2014-07-21

References

→ the Explorer  ·  watch your stack  ·  NVD