Unrated severityNVD Advisory· Published Jun 13, 2014· Updated May 6, 2026
CVE-2014-2303
CVE-2014-2303
Description
Multiple SQL injection vulnerabilities in the file browser component (we_fs.php) in webEdition CMS before 6.2.7-s1.2 and 6.3.x through 6.3.8 before -s1 allow remote attackers to execute arbitrary SQL commands via the (1) table or (2) order parameter.
Affected products
3cpe:2.3:a:webedition:webedition_cms:6.2.7.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:webedition:webedition_cms:6.2.7.0:*:*:*:*:*:*:*
- cpe:2.3:a:webedition:webedition_cms:6.3.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:webedition:webedition_cms:6.3.8.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- packetstormsecurity.com/files/126862/webEdition-CMS-6.3.8.0-svn6985-SQL-Injection.htmlnvdExploit
- seclists.org/fulldisclosure/2014/May/148nvdExploit
- www.securityfocus.com/bid/67689nvdExploit
- www.redteam-pentesting.de/en/advisories/rt-sa-2014-005/-sql-injection-in-webedition-cms-file-browsernvdExploit
- www.webedition.org/de/aktuelles/allgemein/Wichtiges-Sicherheitsupdate-fuer-CMS-webEdition-veroeffentlichtnvdVendor Advisory
- www.securityfocus.com/archive/1/532231/100/0/threadednvd
News mentions
0No linked articles in our index yet.