← Back

CVE-2014-1401

nvd nist
Published: Feb 11, 2014Modified: Apr 29, 2026

JSON object

Loading...
6.5
Vector
AV:N/AC:L/Au:S/C:P/I:P/A:P
Exploitability: 8.0 / Impact: 6.4
Source: NVD

Description

Multiple SQL injection vulnerabilities in AuraCMS 2.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) search parameter to mod/content/content.php or (2) CLIENT_IP, (3) X_FORWARDED_FOR, (4) X_FORWARDED, (5) FORWARDED_FOR, or (6) FORWARDED HTTP header to index.php.

Affected (13)

Products: Auracms: Auracms
1 product
Auracms
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Auracms
Up to 2.3
Version 1.0
Version 1.1
Version 1.2
Version 1.3
Version 1.5
Version 1.61
Version 1.62
Version 2.0
Version 2.1
Version 2.2.1
Version 2.2.2
Version 2.2

Timeline

No history available yet.