CVE-2014-2022

Published
View on NVD ↗
CVSS v3
N/A
CVSS v2
7.1
HIGH
Affected
1
PROJECT

Description

SQL injection vulnerability in includes/api/4/breadcrumbs_create.php in vBulletin 4.2.2, 4.2.1, 4.2.0 PL2, and earlier allows remote authenticated users to execute arbitrary SQL commands via the conceptid argument in an xmlrpc API request.

Vulnerability Notes, PoC Exploits and Write-Ups for security issues disclosed by tintinweb
GitHubGitHub
265