VulnerabilityModified
CVE-2014-8351
SQL injection vulnerability in info.php in French National Commission on Informatics and Liberty (aka CNIL) CookieViz before 1.0.1 allows remote web servers to execute arbitrary SQL commands via the domain parameter.
HIGH 7.5EPSS 1.66%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.66%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SQL injection vulnerability in info.php in French National Commission on Informatics and Liberty (aka CNIL) CookieViz before 1.0.1 allows remote web servers to execute arbitrary SQL commands via the domain parameter.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.66% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- french national commission on informatics and liberty/cookieviz
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/128960/CNIL-CookieViz-Cross-Site-Scripting-SQL-Injection.htmlExploit
- http://seclists.org/fulldisclosure/2014/Nov/3Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98454
- https://github.com/LaboCNIL/CookieViz/commit/489b6050f6c53fe7b24c4bed3eeb9c25543960e2Patch
- http://packetstormsecurity.com/files/128960/CNIL-CookieViz-Cross-Site-Scripting-SQL-Injection.htmlExploit
- http://seclists.org/fulldisclosure/2014/Nov/3Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98454
- https://github.com/LaboCNIL/CookieViz/commit/489b6050f6c53fe7b24c4bed3eeb9c25543960e2Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.