CVE-2014-9464 Information
Feb 14, 2021
cve
Description
SQL injection vulnerability in Category.php in Microweber CMS 0.95 before 20141209 allows remote attackers to execute arbitrary SQL commands via the category parameter when displaying a category related to the $parent_id variable.
Reference
https://github.com/microweber/microweber/commit/4ee09f9dda35cd1b15daa351f335c2a4a0538d29 https://www.youtube.com/watch?v=SSE8Xj_-QaQ
Share on: