// For flags

CVE-2013-7138

Horizon QCMS 4.0 SQL Injection / Directory Traversal

Severity Score

5.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Directory traversal vulnerability in lib/functions/d-load.php in Horizon Quick Content Management System (QCMS) 4.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the start parameter.

Vulnerabilidad de recorrido de directorios en lib/functions/d-load.php de Horizon Quick Content Management System (QCMS) 4.0 y anteriores permite a atacantes remotos leer archivos de forma arbitraria a través de un .. (punto punto) en el parámetro start.

Horizon QCMS version 4.0 suffers from remote SQL injection and directory traversal vulnerabilities.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2013-12-18 CVE Reserved
  • 2014-01-08 CVE Published
  • 2024-01-08 EPSS Updated
  • 2024-08-06 CVE Updated
  • 2024-08-06 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (2)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Horizon Quick Content Management System Project
Search vendor "Horizon Quick Content Management System Project"
Horizon Quick Content Management System
Search vendor "Horizon Quick Content Management System Project" for product "Horizon Quick Content Management System"
<= 4.0
Search vendor "Horizon Quick Content Management System Project" for product "Horizon Quick Content Management System" and version " <= 4.0"
-
Affected
Horizon Quick Content Management System Project
Search vendor "Horizon Quick Content Management System Project"
Horizon Quick Content Management System
Search vendor "Horizon Quick Content Management System Project" for product "Horizon Quick Content Management System"
3.2
Search vendor "Horizon Quick Content Management System Project" for product "Horizon Quick Content Management System" and version "3.2"
a
Affected
Horizon Quick Content Management System Project
Search vendor "Horizon Quick Content Management System Project"
Horizon Quick Content Management System
Search vendor "Horizon Quick Content Management System Project" for product "Horizon Quick Content Management System"
3.3
Search vendor "Horizon Quick Content Management System Project" for product "Horizon Quick Content Management System" and version "3.3"
-
Affected
Horizon Quick Content Management System Project
Search vendor "Horizon Quick Content Management System Project"
Horizon Quick Content Management System
Search vendor "Horizon Quick Content Management System Project" for product "Horizon Quick Content Management System"
3.4
Search vendor "Horizon Quick Content Management System Project" for product "Horizon Quick Content Management System" and version "3.4"
-
Affected
Horizon Quick Content Management System Project
Search vendor "Horizon Quick Content Management System Project"
Horizon Quick Content Management System
Search vendor "Horizon Quick Content Management System Project" for product "Horizon Quick Content Management System"
3.5.1
Search vendor "Horizon Quick Content Management System Project" for product "Horizon Quick Content Management System" and version "3.5.1"
-
Affected
Horizon Quick Content Management System Project
Search vendor "Horizon Quick Content Management System Project"
Horizon Quick Content Management System
Search vendor "Horizon Quick Content Management System Project" for product "Horizon Quick Content Management System"
3.5.2
Search vendor "Horizon Quick Content Management System Project" for product "Horizon Quick Content Management System" and version "3.5.2"
-
Affected