7.5
CVSSv2

CVE-2007-1417

Published: 12/03/2007 Updated: 16/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in index.php in HC NEWSSYSTEM 1.0-4 allows remote malicious users to execute arbitrary SQL commands via the ID parameter in a komm aktion.

Vulnerable Product Search on Vulmon Subscribe to Product

hc design newssystem 1.4

hc design newssystem 1.0

Exploits

HC NEWSSYSTEM 10-4 (indexphp "ID") Blind SQL Injection Type : SQL Injection Release Date : {2007-03-08} Product / Vendor : HC Design News Publisher wwwhcdesignat/demo Bug : localhost/script/indexphp?option=news&aktion=komm&ID=-SQL Inj- SQL Inj Code : Admin Username/Password Query localhost/path/index ...