High severity8.8NVD Advisory· Published Apr 24, 2017· Updated May 13, 2026
CVE-2015-7569
CVE-2015-7569
Description
SQL injection vulnerability in "yeager/y.php/tab_USERLIST" in Yeager CMS 1.2.1 allows local users to execute arbitrary SQL commands via the "pagedir_orderby" parameter.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- seclists.org/fulldisclosure/2016/Feb/44nvdMailing ListPatchThird Party Advisory
- packetstormsecurity.com/files/135716/Yeager-CMS-1.2.1-File-Upload-SQL-Injection-XSS-SSRF.htmlnvdExploitPatchThird Party AdvisoryVDB Entry
- www.securityfocus.com/archive/1/537493/100/0/threadednvdExploitThird Party AdvisoryVDB Entry
- www.exploit-db.com/exploits/39436/nvdExploitPatchThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.