CVE-2014-8339
nuevolab nuevoplayer for ClipShare < 8.0 - SQL Injection via midroll.php ch Parameter
Title source: llmDescription
SQL injection vulnerability in midroll.php in Nuevolab Nuevoplayer for ClipShare 8.0 and earlier allows remote attackers to execute arbitrary SQL commands via the ch parameter.
References (5)
Core 5
Core References
Exploit x_refsource_misc
http://www.youtube.com/watch?v=_-oOI1LnEdk
Exploit, Third Party Advisory x_refsource_misc
http://packetstormsecurity.com/files/128909/Nuevolabs-Nuevoplayer-For-Clipshare-SQL-Injection.html
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/533847/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/98393
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/70833
Scores
EPSS
0.0209
EPSS Percentile
79.6%
Details
CWE
CWE-89
Status
published
Products (2)
clip-share/clipshare
< 8.0
nuevolab/nuevoplayer
Published
Nov 04, 2014
Tracked Since
Feb 18, 2026