CVE-2014-3810

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
19/06/2014
Last modified:
12/04/2025

Description

SQL injection vulnerability in administration/profiles.php in BoonEx Dolphin 7.1.4 and earlier allows remote authenticated administrators to execute arbitrary SQL commands via the members[] parameter. NOTE: this can be exploited by remote attackers by leveraging CVE-2014-4333.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:boonex:dolphin:*:*:*:*:*:*:*:* 7.1.4 (including)
cpe:2.3:a:boonex:dolphin:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:boonex:dolphin:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:boonex:dolphin:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:boonex:dolphin:7.0.3:*:*:*:*:*:*:*
cpe:2.3:a:boonex:dolphin:7.0.3:beta:*:*:*:*:*:*
cpe:2.3:a:boonex:dolphin:7.0.4:*:*:*:*:*:*:*
cpe:2.3:a:boonex:dolphin:7.0.5:*:*:*:*:*:*:*
cpe:2.3:a:boonex:dolphin:7.0.6:*:*:*:*:*:*:*
cpe:2.3:a:boonex:dolphin:7.0.7:*:*:*:*:*:*:*
cpe:2.3:a:boonex:dolphin:7.0.8:*:*:*:*:*:*:*
cpe:2.3:a:boonex:dolphin:7.0.9:*:*:*:*:*:*:*
cpe:2.3:a:boonex:dolphin:7.1.0:*:*:*:*:*:*:*
cpe:2.3:a:boonex:dolphin:7.1.0:b1:*:*:*:*:*:*
cpe:2.3:a:boonex:dolphin:7.1.0:b2:*:*:*:*:*:*