Absolutengine Absolut Engine vulnerabilities
2 known vulnerabilities affecting absolutengine/absolut_engine.
Total CVEs
2
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
MEDIUM1LOW1
Vulnerabilities
Page 1 of 1
CVE-2014-9435P3MEDIUMCVSS 6.5PoCv1.732015-01-02
CVE-2014-9435 [MEDIUM] CWE-89 CVE-2014-9435: Multiple SQL injection vulnerabilities in Absolut Engine 1.73 allow remote authenticated users to ex
Multiple SQL injection vulnerabilities in Absolut Engine 1.73 allow remote authenticated users to execute arbitrary SQL commands via the (1) sectionID parameter to admin/managersection.php, (2) userID parameter to admin/edituser.php, (3) username parameter to admin/admin.php, or (4) title parameter to admin/managerrelated.php.
nvd
CVE-2014-9434P4LOWCVSS 3.5PoCv1.732015-01-02
CVE-2014-9434 [LOW] CWE-79 CVE-2014-9434: Cross-site scripting (XSS) vulnerability in admin/managerrelated.php in the administrative backend i
Cross-site scripting (XSS) vulnerability in admin/managerrelated.php in the administrative backend in Absolut Engine 1.73 allows remote authenticated users to inject arbitrary web script or HTML via the title parameter.
nvd