← Back

CVE-2014-2022

nvd nist
Published: Oct 15, 2014Modified: May 6, 2026

JSON object

Loading...
7.1
Vector
AV:N/AC:H/Au:S/C:C/I:C/A:C
Exploitability: 3.9 / Impact: 10.0
Source: NVD

Description

SQL injection vulnerability in includes/api/4/breadcrumbs_create.php in vBulletin 4.2.2, 4.2.1, 4.2.0 PL2, and earlier allows remote authenticated users to execute arbitrary SQL commands via the conceptid argument in an xmlrpc API request.

Affected (3)

Products: Vbulletin: Vbulletin
1 product
Vbulletin
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Vbulletin
Up to 4.2.2
Version 4.2.0 pl2
Version 4.2.1

References (10)

Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit

Timeline

No history available yet.