Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

CVE-2014-5387

EPSS 1.65% · P73
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2014-5387

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Multiple SQL injection vulnerabilities in EllisLab ExpressionEngine before 2.9.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) column_filter or (2) category[] parameter to system/index.php or the (3) tbl_sort[0][] parameter in the comment module to system/index.php.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
EllisLab ExpressionEngine SQL注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
EllisLab ExpressionEngine是美国EllisLab公司的一套内容管理系统(CMS),它提供Web发布、模板引擎和附件组件等模块。 EllisLab ExpressionEngine 2.9.1之前版本中存在SQL注入漏洞,该漏洞源于system/index.php脚本没有充分过滤‘column_filter’或‘category[]’参数;system/index.php脚本没有充分过滤comment组件中的‘tbl_sort[0][]’参数。远程攻击者可利用该漏洞执行任意SQL命令
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2014-5387

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2014-5387

登录查看更多情报信息。

Vendor Advisories for CVE-2014-5387 (1)

Exploits & Public PoCs for CVE-2014-5387 (1)

Mailing List Discussions for CVE-2014-5387 (1)

Other References for CVE-2014-5387 (2)

Same Patch Batch · n/a · 2014-11-04 · 46 CVEs total

CVE-2013-7057Axway SecureTransport 跨站请求伪造漏洞
CVE-2014-8584WordPress Web Dorado Spider Video Player插件跨站脚本漏洞
CVE-2014-8586WordPress CP Multi View Event Calendar插件‘calid’参数SQL注入漏洞
CVE-2014-8589SAP Network Interface Router 整数溢出漏洞
CVE-2014-8590SAP NetWeaver Application Server Java XML外部实体漏洞
CVE-2014-8591SAP Internet Communication Manager 拒绝服务漏洞
CVE-2014-8592SAP Host Agent 拒绝服务漏洞
CVE-2014-4311Epicor Enterprise 信息泄露漏洞
CVE-2014-8588SAP HANA SQL注入漏洞
CVE-2014-7176Enalean Tuleap SQL注入漏洞
CVE-2014-8339Nuevolab Nuevoplayer for ClipShare SQL注入漏洞
CVE-2014-8593Allomani Weblinks 跨站脚本漏洞
CVE-2014-4974ESET Personal Firewall NDIS filter内核模式驱动程序信息泄露漏洞
CVE-2014-3660Libxml2 拒绝服务漏洞
CVE-2014-7875HP LaserJet CM3530 Multifunction Printer CC519A和CC520A 远程拒绝服务漏洞
CVE-2014-6130IBM Notes Traveler For Android 信息泄露漏洞
CVE-2014-8474CA Cloud Service Management 安全漏洞
CVE-2014-8473CA Cloud Service Management 跨站请求伪造漏洞
CVE-2014-8472CA Cloud Service Management 安全漏洞
CVE-2014-8471CA Cloud Service Management 安全漏洞

Showing top 20 of 46 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2014-5387

No comments yet


Leave a comment