feedback.filerun.com
http://feedback.filerun.com/topics/189-critical-security-update-available CVE-2017-14738
CRITICAL
FileRun < 2017.09.18 - SQL Injection
Record summary
CVE-2017-14738 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
FileRun (version 2017.09.18 and below) suffers from a remote SQL injection vulnerability due to a failure to sanitize input in the metafield parameter inside the metasearch module (under the search function).
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBFileRun < 2017.09.18 - SQL InjectionExploitDB exploitby SPARCNot analyzed1 file
References
4blog.spentera.com
https://blog.spentera.com/2017/09/29/blind-sql-injection-vulnerability-in-filerun-2017-09-18 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-14738 42922exploit
https://www.exploit-db.com/exploits/42922