Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-4804

Опубликовано: 11 сент. 2007
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

Multiple SQL injection vulnerabilities in AuraCMS 1.5rc allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) hal.php, (2) cetak.php, (3) lihat.php, (4) pesan.php, and (5) teman.php, different vectors than CVE-2007-4171. NOTE: the scripts may be accessed through requests to the product's top-level default URI, using the pilih parameter, in some circumstances.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:auracms:auracms:1.5_rc:*:*:*:*:*:*:*

EPSS

Процентиль: 66%
0.00523
Низкий

7.5 High

CVSS2

Дефекты

CWE-89

Связанные уязвимости

github
почти 4 года назад

Multiple SQL injection vulnerabilities in AuraCMS 1.5rc allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) hal.php, (2) cetak.php, (3) lihat.php, (4) pesan.php, and (5) teman.php, different vectors than CVE-2007-4171. NOTE: the scripts may be accessed through requests to the product's top-level default URI, using the pilih parameter, in some circumstances.

EPSS

Процентиль: 66%
0.00523
Низкий

7.5 High

CVSS2

Дефекты

CWE-89