Vulnerability Description
SQL injection vulnerability in Construtiva CIS Manager allows remote attackers to execute arbitrary SQL commands via the email parameter to autenticar/lembrarlogin.asp.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Construtiva | Cis Manager Cms | - |
Related Weaknesses (CWE)
References
- http://seclists.org/fulldisclosure/2014/May/73Exploit
- http://www.securityfocus.com/archive/1/532155/100/0/threaded
- http://www.securityfocus.com/bid/67442Exploit
- http://seclists.org/fulldisclosure/2014/May/73Exploit
- http://www.securityfocus.com/archive/1/532155/100/0/threaded
- http://www.securityfocus.com/bid/67442Exploit
FAQ
What is CVE-2014-3749?
CVE-2014-3749 is a vulnerability with a CVSS score of 7.5 (HIGH). SQL injection vulnerability in Construtiva CIS Manager allows remote attackers to execute arbitrary SQL commands via the email parameter to autenticar/lembrarlogin.asp.
How severe is CVE-2014-3749?
CVE-2014-3749 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-3749?
Check the references section above for vendor advisories and patch information. Affected products include: Construtiva Cis Manager Cms.