Exploitation Summary
EIP tracks 1 public exploit for CVE-2014-1945.
AI-analyzed exploit summary The advisory details two vulnerabilities in OpenDocMan: a SQL injection via the 'add_value' parameter in '/ajax_udf.php' and an improper access control issue in '/signup.php' allowing privilege escalation. It includes exploitation examples and references to CVE-2014-1945 and CVE-2014-1946.
Description
SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary SQL commands via the add_value parameter.
Exploits (1)
The advisory details two vulnerabilities in OpenDocMan: a SQL injection via the 'add_value' parameter in '/ajax_udf.php' and an improper access control issue in '/signup.php' allowing privilege escalation. It includes exploitation examples and references to CVE-2014-1945 and CVE-2014-1946.