CVE-2014-2531

InterWorx Web Control Panel <5.0.14 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-2531. PoCs published by Eric Flokstra.

AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in InterWorx Web Control Panel by manipulating the 'i' parameter in a POST request to /xhr.php. The payload uses a CASE statement to conditionally sort data based on the first character of the MySQL version, proving lack of input validation.

Description

SQL injection vulnerability in xhr.php in InterWorx Web Control Panel (aka InterWorx Hosting Control Panel and InterWorx-CP) before 5.0.14 build 577 allows remote authenticated users to execute arbitrary SQL commands via the i parameter in a search action to the (1) NodeWorx , (2) SiteWorx, or (3) Resellers interface, as demonstrated by the "or" key in a pgn8state object in an i object in a JSON object.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Eric Flokstra · textwebappsphp
https://www.exploit-db.com/exploits/32516

This exploit demonstrates a SQL injection vulnerability in InterWorx Web Control Panel by manipulating the 'i' parameter in a POST request to /xhr.php. The payload uses a CASE statement to conditionally sort data based on the first character of the MySQL version, proving lack of input validation.

Classification
Working Poc 100%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: InterWorx Web Control Panel 5.0.13 build 574
Auth required
Prerequisites: Access to NodeWorx, Siteworx, or Reseller interface · Valid session token
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/32516
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/531601/100/0/threaded

Scores

EPSS 0.0112
EPSS Percentile 62.1%

Details

CWE
CWE-89
Status published
Products (1)
interworx/web_control_panel < 5.0.13
Published Oct 21, 2014
Tracked Since Feb 18, 2026