← Vulnerability feed

Vulnerability record · CVE-2013-3638 · published 6 February 2020

CVE-2013-3638: Boonex dolphin sql injection vulnerability

Boonex · Dolphin

SQL injection vulnerability in Boonex Dolphin before 7.1.3 allows remote authenticated users to execute arbitrary SQL commands via the 'pathes' parameter in 'categories.php'.

8.8 CVSS 3.1 High EPSS 1.4% · top 28.4% CWE-89 · SQL injection
8.8CVSS 3.1 base score, v2 6.5
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

SQL injection vulnerability in Boonex Dolphin before 7.1.3 allows remote authenticated users to execute arbitrary SQL commands via the 'pathes' parameter in 'categories.php'.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-3638 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2008-3167Boonex dolphin code injection vulnerabilityMultiple PHP remote file inclusion vulnerabilities in BoonEx Dolphin 6.1.2, when register_globals is enabled, allow remote attackers to execute arbit…EPSS 6.5%6.8CVE-2014-4333Boonex dolphin cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in administration/profiles.php in Dolphin 7.1.4 and earlier allows remote attackers to hijack the aut…EPSS 0.94%6.5CVE-2014-3810Boonex dolphin sql injection vulnerabilitySQL injection vulnerability in administration/profiles.php in BoonEx Dolphin 7.1.4 and earlier allows remote authenticated administrators to execute …EPSS 1.7%5.1CVE-2006-5410Boonex dolphin vulnerabilityPHP remote file inclusion vulnerability in templates/tmpl_dfl/scripts/index.php in BoonEx Dolphin 5.2 allows remote attackers to execute arbitrary PH…EPSS 1.5%5.1CVE-2006-4189Boonex dolphin vulnerabilityMultiple PHP remote file inclusion vulnerabilities in Dolphin 5.1 allow remote attackers to execute arbitrary PHP code via a URL in the dir[inc] para…EPSS 6.3%5.0CVE-2011-3728Boonex dolphin information exposure vulnerabilityDolphin 7.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an …EPSS 1.2%4.8CVE-2021-27969Boonex dolphin cross-site scripting vulnerabilityDolphin CMS 7.4.2 is vulnerable to stored XSS via the Page Builder "width" parameter.EPSS 0.67%4.3CVE-2012-0873Boonex dolphin cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in Boonex Dolphin before 7.0.8 allow remote attackers to inject arbitrary web script or HTML via …EPSS 4.3%

Source: NIST National Vulnerability Database (record CVE-2013-3638), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.