7.5
CVSSv2

CVE-2007-1979

Published: 12/04/2007 Updated: 11/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in index.php in the PopnupBlog 2.52 and previous versions module for Xoops allows remote malicious users to execute arbitrary SQL commands via the postid parameter, possibly involving the get_blogid_from_postid function in class/PopnupBlogUtils.php. NOTE: later versions such as 3.03 and 3.05 might also be affected.

Vulnerable Product Search on Vulmon Subscribe to Product

xoops xoops popnupblog

Exploits

<html> <head> <title>XOOPS Module PopnupBlog <= 252 (postid) BLIND SQL Injection Exploit</title> <script type="text/javascript"> //'=============================================================================================== //'[Script Name: XOOPS Module PopnupBlog <= 252 (postid) BLIND SQL Injection Explo ...