CVE-2014-9145 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.1% (pctl 81)
Patch early
A public exploit exists.
Description
Multiple SQL injection vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an edit action to dapur/index.php; (2) cat, (3) user, or (4) level parameter to dapur/apps/app_article/controller/article_list.php; or (5) email parameter in an email action or (6) username parameter in a user action to dapur/apps/app_user/controller/check_user.php.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.07% — more likely to be exploited than 81% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2015-04-14 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| fiyo | fiyo cms |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | 2015-03-31 |
References
→ the Explorer · watch your stack · NVD