CVE-2014-8366
openSIS 4.5-5.3 - SQL Injection via Username and Password Parameters
Title source: llmDescription
SQL injection vulnerability in openSIS 4.5 through 5.3 allows remote attackers to execute arbitrary SQL commands via the Username and password to index.php.
References (3)
Core 3
Core References
Exploit mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Jun/151
Exploit x_refsource_misc
http://packetstormsecurity.com/files/127284/openSIS-5.3-SQL-Injection.html
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/59114
Scores
EPSS
0.0207
EPSS Percentile
79.4%
Details
CWE
CWE-89
Status
published
Products (2)
os4ed/opensis
4.5
os4ed/opensis
5.3
Published
Oct 20, 2014
Tracked Since
Feb 18, 2026