7.5
CVE-2007-1575
- EPSS 2.02%
- Veröffentlicht 21.03.2007 21:19:00
- Zuletzt bearbeitet 16.06.2026 22:37:51
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Multiple SQL injection vulnerabilities in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allow remote authenticated users to execute arbitrary SQL commands via (1) unspecified vectors to the (a) calendar and (2) search modules, and an (2) unspecified cookie when the user logs out.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.02% | 0.784 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://secunia.com/advisories/24509
http://secunia.com/advisories/25748
http://security.gentoo.org/glsa/glsa-200706-07.xml
http://securityreason.com/securityalert/2466
http://www.nruns.com/security_advisory_phprojekt_sql_injection.php
http://www.phprojekt.com/index.php?name=News&file=article&sid=276
http://www.securityfocus.com/archive/1/462789/100/0/threaded
http://www.securityfocus.com/bid/22955