HTTP: Fork CMS CVE-2015-1467 SQL Injection

This signature detects attempts to exploit a known vulnerability against Fork CMS. Attackers can execute arbitrary SQL commands.

Extended Description

Multiple SQL injection vulnerabilities in Translations in Fork CMS before 3.8.6 allow remote authenticated users to execute arbitrary SQL commands via the (1) language[] or (2) type[] parameter to private/en/locale/index.

Affected Products

Fork-cms fork_cms

Short Name
HTTP:SQL:INJ:FORK-CMS-SQL-INJ
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CMS CVE-2015-1467 Fork Injection SQL
Release Date
08/22/2019
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
False Positive
Unknown
Vendors

Fork-cms

CVSS Score

7.5

Found a potential security threat?