7.5
CVSSv2

CVE-2007-3808

Published: 17/07/2007 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in includes/search.php in paFileDB 3.6 allows remote malicious users to execute arbitrary SQL commands via the categories[] parameter in a search action to index.php, a different vector than CVE-2005-2000.

Vulnerable Product Search on Vulmon Subscribe to Product

php arena pafiledb 3.6

Exploits

Site: wwwphparenanet/pafiledb Description: SQL injection (categories) in includes/searchphp Code: $results = $db->GetArray("SELECT * FROM "$dbPrefix"files WHERE ("$searchin") AND file_catid IN ("implode(',',$_POST['categories'])")"); Comment:"ouuch" SQL: ) UNION SELECT ALL null,user_username,user_password,null,null,null,null,nu ...