Unrated severityNVD Advisory· Published Oct 10, 2014· Updated May 6, 2026
CVE-2014-7201
CVE-2014-7201
Description
Multiple SQL injection vulnerabilities in the search function in pi1/class.tx_dmmjobcontrol_pi1.php in the JobControl (dmmjobcontrol) extension 2.14.0 and earlier for TYPO3 allow remote attackers to execute arbitrary SQL commands via the (1) education, (2) region, or (3) sector fields, as demonstrated by the tx_dmmjobcontrol_pi1[search][sector][] parameter to jobs/.
Affected products
1- cpe:2.3:a:kevin_renskers:dmmjobcontrol:*:*:*:*:*:typo3:*:*Range: <=2.14.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- packetstormsecurity.com/files/128446/Typo3-JobControl-2.14.0-Cross-Site-Scripting-SQL-Injection.htmlnvdExploit
- seclists.org/fulldisclosure/2014/Sep/89nvdExploit
- www.mogwaisecurity.de/advisories/MSA-2014-02.txtnvdExploit
- typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2014-012nvd
- www.securityfocus.com/bid/70155nvd
News mentions
0No linked articles in our index yet.