HomeVbulletinCVE-2014-2022

CVE-2014-2022

UNKNOWN
7.1CVSS
Published: 2014-10-15
Updated: 2025-04-12
AI Analysis

Description

SQL injection vulnerability in includes/api/4/breadcrumbs_create.php in vBulletin 4.2.2, 4.2.1, 4.2.0 PL2, and earlier allows remote authenticated users to execute arbitrary SQL commands via the conceptid argument in an xmlrpc API request.

CVSS Metrics

Vector
AV:N/AC:H/Au:S/C:C/I:C/A:C
Access Vector
network
Access Cmplx
high
Auth
single
Confidentiality
complete
Integrity
complete
Availability
complete
Weaknesses
CWE-89

Metadata

Primary Vendor
VBULLETIN
Published
10/15/2014
Last Modified
4/12/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

vbulletin : vbulletinvbulletin : vbulletinvbulletin : vbulletin

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2014-2022 | UNKNOWN Severity | CVEDatabase.com | CVEDatabase.com