7.5
CVE-2007-1363
- EPSS 1.07%
- Veröffentlicht 11.04.2007 22:19:00
- Zuletzt bearbeitet 16.06.2026 22:37:26
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Multiple SQL injection vulnerabilities in DropAFew before 0.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in the delete action in (a) search.php or (b) search-pda.php, or the (2) calories parameter in a save action in editlogcal.php.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.07% | 0.604 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://secunia.com/advisories/24861
http://www.cynops.de/advisories/CVE-2007-1363.txt
http://www.dropafew.com/sphpblog/comments.php?y=07&m=04&entry=entry070403-224437
http://www.securityfocus.com/bid/23400
https://exchange.xforce.ibmcloud.com/vulnerabilities/33560