Record summary

CVE-2014-9148 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.

Description

Fiyo CMS 2.0.1.8 allows remote attackers to bypass intended access restrictions and execute the (1) "Install and Update" or (2) Backup super administrator function via the view parameter in a direct request to fiyo/dapur.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBFiyo CMS 2.0.1.8 - Multiple VulnerabilitiesExploitDB exploitby MahendraNot analyzed1 file

linked to 5 vulnerabilities

ExploitDB

PoC details

References

4