CVE-2014-2317

SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary SQL commands via the table parameter.  NOTE: some of these details are obtained from third party information.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 57%
VendorProductVersion
opendocmanopendocman
𝑥
≤ 1.2.7.1
opendocmanopendocman
1.2.6.2
opendocmanopendocman
1.2.6.2:a
opendocmanopendocman
1.2.6.2:b
opendocmanopendocman
1.2.6.3
opendocmanopendocman
1.2.6.3:a
opendocmanopendocman
1.2.6.5
opendocmanopendocman
1.2.6.6
opendocmanopendocman
1.2.6.7
opendocmanopendocman
1.2.6.7:beta
opendocmanopendocman
1.2.6.8
opendocmanopendocman
1.2.7
𝑥
= Vulnerable software versions