CVE-2014-2303

webEdition CMS <6.3.8-s1 - SQL Injection

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in the file browser component (we_fs.php) in webEdition CMS before 6.2.7-s1.2 and 6.3.x through 6.3.8 before -s1 allow remote attackers to execute arbitrary SQL commands via the (1) table or (2) order parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by RedTeam Pentesting GmbH · textwebappsphp
https://www.exploit-db.com/exploits/39206

Scores

EPSS 0.0412
EPSS Percentile 88.7%

Details

CWE
CWE-89
Status published
Products (3)
webedition/webedition_cms 6.2.7.0
webedition/webedition_cms 6.3.3.0
webedition/webedition_cms 6.3.8.0
Published Jun 13, 2014
Tracked Since Feb 18, 2026