CVE-2014-8366

openSIS 4.5-5.3 - SQL Injection via Username and Password Parameters

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in openSIS 4.5 through 5.3 allows remote attackers to execute arbitrary SQL commands via the Username and password to index.php.

References (3)

Core 3
Core References
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Jun/151
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59114

Scores

EPSS 0.0207
EPSS Percentile 79.4%

Details

CWE
CWE-89
Status published
Products (2)
os4ed/opensis 4.5
os4ed/opensis 5.3
Published Oct 20, 2014
Tracked Since Feb 18, 2026