7.5
CVSSv2

CVE-2007-1016

Published: 21/02/2007 Updated: 08/03/2011
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in Aktueldownload Haber script allows remote malicious users to execute arbitrary SQL commands via certain vectors related to the HaberDetay.asp and rss.asp components, and the id and kid parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: the combination of the HaberDetay.asp component and the id parameter is already covered by another February 2007 CVE candidate.

Vulnerable Product Search on Vulmon Subscribe to Product

aktueldownload aktueldownload haber script

Exploits

----------------------------------------------------------------------- Aktueldownload Haber scripti (id) Remote SQL Injection Vulnerability ----------------------------------------------------------------------- Bulan: xoron xoroninfo - xoronbiz ----------------------------------------------------------------------- Exploit: HaberDetaya ...