← Back

CVE-2014-3773

nvd nist
Published: Aug 7, 2014Modified: May 6, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Multiple SQL injection vulnerabilities in TeamPass before 2.1.20 allow remote attackers to execute arbitrary SQL commands via the login parameter in a (1) send_pw_by_email or (2) generate_new_password action in sources/main.queries.php; iDisplayStart parameter to (3) datatable.logs.php or (4) a file in source/datatable/; or iDisplayLength parameter to (5) datatable.logs.php or (6) a file in source/datatable/; or allow remote authenticated users to execute arbitrary SQL commands via a sSortDir_ parameter to (7) datatable.logs.php or (8) a file in source/datatable/.

Affected (13)

Products: Teampass: Teampass
1 product
Teampass
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Teampass
Up to 2.1.20
Version 2.1.10
Version 2.1.13
Version 2.1.14
Version 2.1.15
Version 2.1.18
Version 2.1.19
Version 2.1.1
Version 2.1.2
Version 2.1.3
Version 2.1.4
Version 2.1.5
Version 2.1

Timeline

No history available yet.