CVE-2013-7139

Horizon QCMS <4.0 - SQL Injection

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in download.php in Horizon Quick Content Management System (QCMS) 4.0 and earlier allows remote to execute arbitrary SQL commands via the category parameter.

Exploits (1)

exploitdb WRITEUP
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/30917

References (2)

Core 2
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/64715

Scores

EPSS 0.0033
EPSS Percentile 56.0%

Details

CWE
CWE-89
Status published
Products (6)
cynthia_fridsma/horizon_quick_content_management_system 3.2 a
cynthia_fridsma/horizon_quick_content_management_system 3.3
cynthia_fridsma/horizon_quick_content_management_system 3.4
cynthia_fridsma/horizon_quick_content_management_system 3.5.1
cynthia_fridsma/horizon_quick_content_management_system 3.5.2
cynthia_fridsma/horizon_quick_content_management_system < 4.0
Published Jan 09, 2014
Tracked Since Feb 18, 2026