CVE-2014-2847

CIS Manager CMS - SQL Injection via TroncoID Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-2847. PoCs published by felipe andrian.

AI-analyzed exploit summary This is a writeup describing a SQL injection vulnerability in CIS Manager CMS, specifically in the default.asp file. It provides a dork for finding vulnerable sites and a basic exploit URL structure but lacks executable code.

Description

SQL injection vulnerability in default.asp in CIS Manager CMS allows remote attackers to execute arbitrary SQL commands via the TroncoID parameter.

Exploits (1)

exploitdb WRITEUP
by felipe andrian · textwebappsasp
https://www.exploit-db.com/exploits/32660

This is a writeup describing a SQL injection vulnerability in CIS Manager CMS, specifically in the default.asp file. It provides a dork for finding vulnerable sites and a basic exploit URL structure but lacks executable code.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: CIS Manager CMS
No auth needed
Prerequisites: A vulnerable instance of CIS Manager CMS
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/32660
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/66590
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/105364

Scores

EPSS 0.0131
EPSS Percentile 66.8%

Details

CWE
CWE-89
Status published
Products (1)
construtiva/cis_manager_cms
Published Apr 11, 2014
Tracked Since Feb 18, 2026