Skip to content

CVE-2014-2540

SQL injection vulnerability in OrbitScripts Orbit Open Ad Server before 1.1.1 allows remote attackers to execute arbitrary SQL commands via the site_directory_sort_field parameter to guest/site_directory.

Ver en NVD

Severidad

N/A

EPSS

Probabilidad de explotación (próx. 30 días): 0.0169 (1.7%)
Percentil: 82.4%
EPSS: 2026-05-06

Afecta

orbitscripts:orbit_open_ad_server

Descripción técnica

SQL injection vulnerability in OrbitScripts Orbit Open Ad Server before 1.1.1 allows remote attackers to execute arbitrary SQL commands via the site_directory_sort_field parameter to guest/site_directory.

Publicada: 11/4/2014, 14:55:05
Última modificación: 6/5/2026, 22:30:45

Referencias

InicioEventosBlogRecursosEquipo