CVE-2014-7201

TYPO3 dmmjobcontrol <2.14.0 - SQL Injection

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in the search function in pi1/class.tx_dmmjobcontrol_pi1.php in the JobControl (dmmjobcontrol) extension 2.14.0 and earlier for TYPO3 allow remote attackers to execute arbitrary SQL commands via the (1) education, (2) region, or (3) sector fields, as demonstrated by the tx_dmmjobcontrol_pi1[search][sector][] parameter to jobs/.

Exploits (1)

exploitdb WRITEUP
by Adler Freiheit · textwebappsphp
https://www.exploit-db.com/exploits/34800

References (5)

Core 5

Scores

EPSS 0.0108
EPSS Percentile 77.9%

Details

CWE
CWE-89
Status published
Products (1)
kevin_renskers/dmmjobcontrol < 2.14.0
Published Oct 10, 2014
Tracked Since Feb 18, 2026