7.5
CVSSv2

CVE-2007-2792

Published: 22/05/2007 Updated: 11/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the Yet another Newsletter Component (aka YaNC or com_yanc) component prior to 1.5 beta 3 for Mambo and Joomla! allows remote malicious users to execute arbitrary SQL commands via the listid parameter to index.php. NOTE: some of these details are obtained from third party information.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

com yanc com yanc 1.4_beta

Exploits

------------------------------ ------------------------------- Mambo com_yanc v14 beta (id) Blind Remote SQL Injection Vuln ------------------------------------------------------------- Bulan: Cyber-Security ------------------------------------------------------------- Exploit: indexphp?option=com_yanc&Itemid=9999999&listid=9999999/* ...
============================================================================== [»] Joomla com_yanc Remote Sql Injection Vulnerability ============================================================================== [»] Script: [Joomla] [»] Language: [ PHP ] [»] Founder: [ Snakespc Email:super_cristal@hotmailcom - Site:sec-warcom/cc> ] ...