7.5
CVSSv2

CVE-2007-2312

Published: 26/04/2007 Updated: 16/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in the Virtual War (VWar) 1.5.0 R15 module for PHP-Nuke allow remote malicious users to execute arbitrary SQL commands via the n parameter to extra/online.php and other unspecified scripts in extra/. NOTE: this might be same vulnerability as CVE-2006-4142; however, there is an intervening vendor fix announcement.

Vulnerable Product Search on Vulmon Subscribe to Product

vwar virtual war 1.5.0_r15

Exploits

:[ insecurity research team ]: ______:__________:____ : | |/ \:/ ___// __ \:/ _\: : | | | \\____\\ ___/\ /__ : : |__|___| /____ >\___ >\___ >: : \/ :\/: \/ :\/: : advisory : :: 1oo82oo6 Affected Application: ...