packetstormsecurity.com
http://packetstormsecurity.com/files/126866/Videos-Tube-1.0-SQL-Injection.html CVE-2014-3962
Videos Tube 1.0 - Multiple SQL Injections
Record summary
CVE-2014-3962 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Multiple SQL injection vulnerabilities in Videos Tube 1.0 allow remote attackers to execute arbitrary SQL commands via the url parameter to (1) videocat.php or (2) single.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBVideos Tube 1.0 - Multiple SQL InjectionsExploitDB exploitby Mustafa ALTINKAYNAKNot analyzed1 file
References
558844Third-party advisory
http://secunia.com/advisories/58844 33514exploit
http://www.exploit-db.com/exploits/33514 67766vdb entry
http://www.securityfocus.com/bid/67766 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2014-3962