CVE-2018-14418

In Msvod Cms v10, SQL Injection exists via an images/lists?cid= URI.
References
Link Resource
https://www.wtfsec.org/2583/msvod-v10-sql-injection/ Exploit Third Party Advisory
https://www.exploit-db.com/exploits/45062/ Exploit Third Party Advisory VDB Entry
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:msvod:msvod_cms:10:*:*:*:*:*:*:*

Information

Published : 2018-07-19 18:29

Updated : 2018-09-17 07:13


NVD link : CVE-2018-14418

Mitre link : CVE-2018-14418


JSON object : View

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Advertisement

dedicated server usa

Products Affected

msvod

  • msvod_cms