CVE-2014-9464

Microweber CMS <20141209 - SQL Injection

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in Category.php in Microweber CMS 0.95 before 20141209 allows remote attackers to execute arbitrary SQL commands via the category parameter when displaying a category, related to the $parent_id variable.

Exploits (1)

exploitdb WORKING POC
by Pham Kien Cuong · textwebappsphp
https://www.exploit-db.com/exploits/35720

References (2)

Core 2

Scores

EPSS 0.0213
EPSS Percentile 84.2%

Details

CWE
CWE-89
Status published
Products (1)
microweber/microweber < 0.95
Published Jan 03, 2015
Tracked Since Feb 18, 2026