CVE-2014-2022
Published
CVSS v3
N/A
CVSS v2
7.1
HIGH
Affected
1
PROJECT
Description
SQL injection vulnerability in includes/api/4/breadcrumbs_create.php in vBulletin 4.2.2, 4.2.1, 4.2.0 PL2, and earlier allows remote authenticated users to execute arbitrary SQL commands via the conceptid argument in an xmlrpc API request.
Vulnerability Notes, PoC Exploits and Write-Ups for security issues disclosed by tintinweb