Security Advisory
CVE-2014-8294
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
Multiple SQL injection vulnerabilities in Voice Of Web AllMyGuests 0.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) allmyphp_cookie cookie to admin.php or the (2) Username or (3) Password.