Lucene search

K
cveMitreCVE-2014-3757
HistoryMay 15, 2014 - 2:55 p.m.

CVE-2014-3757

2014-05-1514:55:07
CWE-89
mitre
web.nvd.nist.gov
25
cve-2014-3757
sql injection
phpmanufaktur
kitform
keepintouch
kit
vulnerability

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.7

Confidence

Low

EPSS

0.001

Percentile

37.0%

SQL injection vulnerability in sorter.php in the phpManufaktur kitForm extension 0.43 and earlier for the KeepInTouch (KIT) module allows remote attackers to execute arbitrary SQL commands via the sorter_value parameter.

Affected configurations

Nvd
Node
phpmanufakturkitformRange0.43keepintouch
OR
phpmanufakturkitformMatch0.10keepintouch
OR
phpmanufakturkitformMatch0.11keepintouch
OR
phpmanufakturkitformMatch0.12keepintouch
OR
phpmanufakturkitformMatch0.13keepintouch
OR
phpmanufakturkitformMatch0.14keepintouch
OR
phpmanufakturkitformMatch0.15keepintouch
OR
phpmanufakturkitformMatch0.16keepintouch
OR
phpmanufakturkitformMatch0.17keepintouch
OR
phpmanufakturkitformMatch0.18keepintouch
OR
phpmanufakturkitformMatch0.19keepintouch
OR
phpmanufakturkitformMatch0.20keepintouch
OR
phpmanufakturkitformMatch0.21keepintouch
OR
phpmanufakturkitformMatch0.22keepintouch
OR
phpmanufakturkitformMatch0.23keepintouch
OR
phpmanufakturkitformMatch0.24keepintouch
OR
phpmanufakturkitformMatch0.25keepintouch
OR
phpmanufakturkitformMatch0.26keepintouch
OR
phpmanufakturkitformMatch0.27keepintouch
OR
phpmanufakturkitformMatch0.28keepintouch
OR
phpmanufakturkitformMatch0.29keepintouch
OR
phpmanufakturkitformMatch0.30keepintouch
OR
phpmanufakturkitformMatch0.31keepintouch
OR
phpmanufakturkitformMatch0.32keepintouch
OR
phpmanufakturkitformMatch0.33keepintouch
OR
phpmanufakturkitformMatch0.34keepintouch
OR
phpmanufakturkitformMatch0.35keepintouch
OR
phpmanufakturkitformMatch0.36keepintouch
OR
phpmanufakturkitformMatch0.37keepintouch
OR
phpmanufakturkitformMatch0.38keepintouch
OR
phpmanufakturkitformMatch0.39keepintouch
OR
phpmanufakturkitformMatch0.40keepintouch
OR
phpmanufakturkitformMatch0.41keepintouch
OR
phpmanufakturkitformMatch0.42keepintouch
VendorProductVersionCPE
phpmanufakturkitform*cpe:2.3:a:phpmanufaktur:kitform:*:*:*:*:*:keepintouch:*:*
phpmanufakturkitform0.10cpe:2.3:a:phpmanufaktur:kitform:0.10:*:*:*:*:keepintouch:*:*
phpmanufakturkitform0.11cpe:2.3:a:phpmanufaktur:kitform:0.11:*:*:*:*:keepintouch:*:*
phpmanufakturkitform0.12cpe:2.3:a:phpmanufaktur:kitform:0.12:*:*:*:*:keepintouch:*:*
phpmanufakturkitform0.13cpe:2.3:a:phpmanufaktur:kitform:0.13:*:*:*:*:keepintouch:*:*
phpmanufakturkitform0.14cpe:2.3:a:phpmanufaktur:kitform:0.14:*:*:*:*:keepintouch:*:*
phpmanufakturkitform0.15cpe:2.3:a:phpmanufaktur:kitform:0.15:*:*:*:*:keepintouch:*:*
phpmanufakturkitform0.16cpe:2.3:a:phpmanufaktur:kitform:0.16:*:*:*:*:keepintouch:*:*
phpmanufakturkitform0.17cpe:2.3:a:phpmanufaktur:kitform:0.17:*:*:*:*:keepintouch:*:*
phpmanufakturkitform0.18cpe:2.3:a:phpmanufaktur:kitform:0.18:*:*:*:*:keepintouch:*:*
Rows per page:
1-10 of 341

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.7

Confidence

Low

EPSS

0.001

Percentile

37.0%

Related for CVE-2014-3757