7.5

CVE-2007-4956

Multiple SQL injection vulnerabilities in KwsPHP 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the pseudo parameter to login.php, (2) the id parameter to index.php in a carnet editer action in the Member_Space (espace_membre) module, or (3) the typenav parameter to index.php in a browser aff action in the stats module.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
KwsphpKwsphp Version1.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.53% 0.877
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

http://koogar.alorys-hebergement.com/kwsphp/index.php?mod=news&ac=commentaires&id=29
http://osvdb.org/37180
http://osvdb.org/37182
http://secunia.com/advisories/26850
http://www.securityfocus.com/bid/25679
https://exchange.xforce.ibmcloud.com/vulnerabilities/36634
https://exchange.xforce.ibmcloud.com/vulnerabilities/36635
https://exchange.xforce.ibmcloud.com/vulnerabilities/36636
https://www.exploit-db.com/exploits/4412
https://www.exploit-db.com/exploits/4413
https://www.exploit-db.com/exploits/4414