7.5
CVE-2007-3430
- EPSS 1.2%
- Veröffentlicht 27.06.2007 00:30:00
- Zuletzt bearbeitet 16.06.2026 22:42:01
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
SQL injection vulnerability in index.php in Simple Invoices 2007 05 25 allows remote attackers to execute arbitrary SQL commands via the submit parameter in an email action.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Simple Invoices ≫ Simple Invoices Version2007-05-25
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.2% | 0.64 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://osvdb.org/36293
http://secunia.com/advisories/25789
http://www.securityfocus.com/bid/24601
http://www.vupen.com/english/advisories/2007/2310
https://exchange.xforce.ibmcloud.com/vulnerabilities/35021
https://www.exploit-db.com/exploits/4098