CVE-2014-2934

Caldera - SQL Injection

Title source: rule
STIX 2.1

Description

Multiple SQL injection vulnerabilities in Caldera 9.20 allow remote attackers to execute arbitrary SQL commands via the tr parameter to (1) costview2/jobs.php or (2) costview2/printers.php.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Thomas Fischer · textwebappsphp
https://www.exploit-db.com/exploits/39174
exploitdb WORKING POC VERIFIED
by Thomas Fischer · textwebappsphp
https://www.exploit-db.com/exploits/39173

References (1)

Core 1
Core References
Exploit, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/693092

Scores

EPSS 0.0056
EPSS Percentile 68.2%

Details

CWE
CWE-89
Status published
Products (1)
caldera/caldera 9.20
Published May 08, 2014
Tracked Since Feb 18, 2026