Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2015-1514

Multiple SQL injection vulnerabilities in FancyFon FAMOC before 3.17.4 allow (1) remote attackers to execute arbitrary SQL commands via the device ID REST parameter (PATH_INFO) to /ajax.php or (2) remote authenticated users to execute arbitrary SQL commands via the order parameter to index.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 57.5%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2015-1514
  • Fancyfon » Famoc » Version: 3.16.5
    cpe:2.3:a:fancyfon:famoc:3.16.5


Contact Us

Shodan ® - All rights reserved