peter bassill · operator
$ cve CVE-2014-9145 JSON

CVE-2014-9145 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.1% (pctl 81)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an edit action to dapur/index.php; (2) cat, (3) user, or (4) level parameter to dapur/apps/app_article/controller/article_list.php; or (5) email parameter in an email action or (6) username parameter in a user action to dapur/apps/app_user/controller/check_user.php.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.07% — more likely to be exploited than 81% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2015-04-14
Last modified2026-06-17

Affected (1)

VendorProduct
fiyofiyo cms

Public exploits

SourceTitleDate
exploit-dbFiyo CMS 2.0.1.8 - Multiple Vulnerabilities2015-03-31

References

→ the Explorer  ·  watch your stack  ·  NVD