Lucene search

K
cvelistMitreCVELIST:CVE-2015-8355
HistoryAug 24, 2017 - 9:00 p.m.

CVE-2015-8355

2017-08-2421:00:00
mitre
www.cve.org
2

AI Score

9.2

Confidence

High

EPSS

0.001

Percentile

44.0%

Multiple SQL injection vulnerabilities in the orion.extfeedbackform module before 2.1.3 for Bitrix allow remote authenticated users to execute arbitrary SQL commands via the (1) order or (2) “by” parameter to admin/orion.extfeedbackform_efbf_forms.php.

AI Score

9.2

Confidence

High

EPSS

0.001

Percentile

44.0%

Related for CVELIST:CVE-2015-8355