7.5

CVE-2007-3250

SQL injection vulnerability in mod_banners.php in Elxis CMS before 2006.4 20070613 allows remote attackers to execute arbitrary SQL commands via the mb_tracker cookie.  NOTE: the product was patched without updating the version number; later downloads of 2006.4 are not affected.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Elxis ≫ Elxis Cms Version 2006.1
Elxis ≫ Elxis Cms Version 2006.2
Elxis ≫ Elxis Cms Version 2006.3
Elxis ≫ Elxis Cms Version 2006.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.33% 0.673
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://osvdb.org/36305
http://secunia.com/advisories/25684
http://securityreason.com/securityalert/2806
http://www.elxis.org/index.php?option=com_mtree&task=viewlink&link_id=98&Itemid=140
Patch
http://www.securityfocus.com/archive/1/471399/100/0/threaded
http://www.securityfocus.com/bid/24478
Patch
http://www.vupen.com/english/advisories/2007/2218
https://exchange.xforce.ibmcloud.com/vulnerabilities/34873