7.5

CVE-2007-0759

Exploit
Multiple SQL injection vulnerabilities in EasyMoblog 0.5.1 allow remote attackers to execute arbitrary SQL commands via the (1) i or (2) post_id parameter to add_comment.php, which triggers an injection in libraries.inc.php; or (3) the i parameter to list_comments.php, which triggers an injection in libraries.inc.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Umberto CalderaEasymoblog Version0.5.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.21% 0.646
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/19370
Vendor Advisory
http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0052.html
http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0054.html
http://osvdb.org/33636
http://www.securityfocus.com/bid/22369
Exploit
http://www.zion-security.com/text/Sql_Vulnerability_EasymoBlog%232.txt
Exploit
http://www.zion-security.com/text/Sql_Vulnerability_EasymoBlog.txt
Exploit