7.5
CVSSv2

CVE-2007-3563

Published: 04/07/2007 Updated: 15/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in includes/view_page.php in AV Arcade 2.1b allows remote malicious users to execute arbitrary SQL commands via the id parameter in a view_page action to index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

avscripts av arcade 2.1b

Exploits

Web: AV Arcade 21b Site : wwwavscriptsnet Dork : "Powered By AV Arcade" Author: Kw3rLn [ teh_lost_byte[at]YaHoO[d0t]Com ] Romanian Security Team [Ethical Hacking] - hTTp://RSTZONEnET Description: SQL injection in $id of includes/view_pagephp Exploit: /indexphp?task=view_page&id=-1%20UNION%20SELECT%201,username,password%20FROM%20ava_us ...