7.5
CVSSv2

CVE-2007-3646

Published: 10/07/2007 Updated: 19/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in index.php in FlashGameScript 1.7 and previous versions allows remote malicious users to execute arbitrary SQL commands via the user parameter in a member action.

Vulnerable Product Search on Vulmon Subscribe to Product

flashgamescript flashgamescript 1.5.4

flashgamescript flashgamescript 1.7

Exploits

############################################### ### FlashGameScript <= 17 (memberphp)($user) SQL-Injection Exploit ############################################### ### Vulnrability Discovered By: Xenduer77 ### ---July 7th, 2007 ############################################### {$user} Is passed straight to the query without being filtered #### ...