CVE-2014-8294

Voice Of Web AllMyGuests 0.4.1 - SQL Injection via Cookie or Credentials

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in Voice Of Web AllMyGuests 0.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) allmyphp_cookie cookie to admin.php or the (2) Username or (3) Password.

References (1)

Core 1

Scores

EPSS 0.0126
EPSS Percentile 66.5%

Details

CWE
CWE-89
Status published
Products (1)
php_resource/voice_of_web_allmyguests 0.4.1
Published Oct 15, 2014
Tracked Since Feb 18, 2026