6.8

CVE-2007-0693

SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a newslist action.  NOTE: this issue can produce resultant cross-site scripting (XSS).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dian GemilangDgnews Version1.5.1
Dian GemilangDgnews Version2.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.55% 0.719
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/25438
http://securityreason.com/securityalert/2740
http://www.netvigilance.com/advisory0022
http://www.osvdb.org/34227
Vendor Advisory
http://www.securityfocus.com/archive/1/469828/100/0/threaded
http://www.securityfocus.com/bid/24201
http://www.vupen.com/english/advisories/2007/1981
https://exchange.xforce.ibmcloud.com/vulnerabilities/34539