CVE-2014-4307

WebTitan < 4.01 - SQL Injection via categories-x.php sortkey Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-4307. PoCs published by SEC Consult.

AI-analyzed exploit summary This is a detailed security advisory describing multiple critical vulnerabilities in WebTitan 4.01 (Build 68), including SQL injection, remote command execution, path traversal, and unprotected access. It provides proof-of-concept examples for each vulnerability.

Description

SQL injection vulnerability in categories-x.php in WebTitan before 4.04 allows remote attackers to execute arbitrary SQL commands via the sortkey parameter.

Exploits (1)

exploitdb WRITEUP
by SEC Consult · textwebappsphp
https://www.exploit-db.com/exploits/33699

This is a detailed security advisory describing multiple critical vulnerabilities in WebTitan 4.01 (Build 68), including SQL injection, remote command execution, path traversal, and unprotected access. It provides proof-of-concept examples for each vulnerability.

Classification
Writeup 100%
Attack Type
Rce | Sqli | Info Leak | Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: WebTitan 4.01 (Build 68)
No auth needed
Prerequisites: Network access to the WebTitan interface
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

EPSS 0.0224
EPSS Percentile 80.5%

Details

CWE
CWE-89
Status published
Products (1)
webtitan/webtitan < 4.01
Published Jun 18, 2014
Tracked Since Feb 18, 2026