Vulnerabilities > PMB Services > PMB > 4.1.3

DATE CVE VULNERABILITY TITLE RISK
2015-01-02 CVE-2014-9457 SQL Injection vulnerability in PMB Services PMB 4.1.3
SQL injection vulnerability in classes/mono_display.class.php in PMB 4.1.3 and earlier allows remote authenticated users to execute arbitrary SQL commands via the id parameter to catalog.php.
network
low complexity
pmb-services CWE-89
6.5