CVE-2014-9254
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 1.3%
from disclosure to weapon0 days
Published on NVDDec 31
1st PoCDec 19
exploitation probability
1.3%top 32% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
bb_func_unsub.php in MiniBB 3.1 before 20141127 uses an incorrect regular expression, which allows remote attackers to conduct SQl injection attacks via the code parameter in an unsubscribe action to index.php.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/35579unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.