7.5
CVSSv2

CVE-2007-3430

Published: 27/06/2007 Updated: 11/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in index.php in Simple Invoices 2007 05 25 allows remote malicious users to execute arbitrary SQL commands via the submit parameter in an email action.

Vulnerable Product Search on Vulmon Subscribe to Product

simple invoices simple invoices 2007-05-25

Exploits

<?/* Exploit Name: Simple Invoices 2007 05 25 (indexphp submit) Remote SQL Injection Exploit Script homepage/download/demo: simpleinvoicesorg/ Discovered by: Kacper (kacper1964@yahoopl) Kacper Hacking & Security Blog: kacperbblogpl/ ^()* => Homepage: devilteameu/ <= *()^ Irc: ircmilw0rmcom:6667 #deviltea ...