CVE-2014-9005

vldPersonals <2.7.1 - SQL Injection

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in vldPersonals before 2.7.1 allow remote attackers to execute arbitrary SQL commands via the (1) country, (2) gender1, or ((3) gender2 parameter in a search action to index.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Mr T · textwebappsphp
https://www.exploit-db.com/exploits/35193

References (2)

Core 2
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/35193
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/98746

Scores

EPSS 0.0025
EPSS Percentile 47.8%

Details

CWE
CWE-89
Status published
Products (1)
vld_interactive/vldpersonals < 2.7
Published Nov 20, 2014
Tracked Since Feb 18, 2026