CVE-2014-3906

OSK Advance-Flow <4.41 - SQL Injection

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in OSK Advance-Flow 4.41 and earlier and Advance-Flow Forms 4.41 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

References (2)

Core 2
Core References
Third Party Advisory third-party-advisory x_refsource_jvndb
http://jvndb.jvn.jp/jvndb/JVNDB-2014-000099
Third Party Advisory third-party-advisory x_refsource_jvn
http://jvn.jp/en/jp/JVN20812625/index.html

Scores

EPSS 0.0116
EPSS Percentile 64.0%

Details

CWE
CWE-89
Status published
Products (2)
kk-osk/advance-flow < 4.41
kk-osk/advance-flow_forms < 4.41
Published Aug 19, 2014
Tracked Since Feb 18, 2026