Unrated severityNVD Advisory· Published Jul 3, 2014· Updated May 6, 2026
CVE-2014-3857
CVE-2014-3857
Description
Multiple SQL injection vulnerabilities in Kerio Control Statistics in Kerio Control (formerly WinRoute Firewall) before 8.3.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) x_16 or (2) x_17 parameter to print.php.
Affected products
2cpe:2.3:a:kerio:control:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:kerio:control:*:*:*:*:*:*:*:*range: <=8.3.1
- cpe:2.3:a:kerio:control:8.3.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- fereidani.com/articles/show/76_kerio_control_8_3_1_boolean_based_blind_sql_injectionnvdExploit
- osvdb.org/show/osvdb/108584nvd
- packetstormsecurity.com/files/127320/Kerio-Control-8.3.1-Blind-SQL-Injection.htmlnvd
- secunia.com/advisories/59215nvd
- www.exploit-db.com/exploits/33954nvd
- www.kerio.com/support/kerio-control/release-historynvd
- www.securityfocus.com/archive/1/532607/100/0/threadednvd
News mentions
0No linked articles in our index yet.