7.5
CVSSv2

CVE-2007-3909

Published: 19/07/2007 Updated: 29/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Bandersnatch 0.4 allow remote malicious users to execute arbitrary SQL commands via the (1) date and (2) limit parameters to index.php, and other unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

bandersnatch bandersnatch 0.4

Exploits

source: wwwsecurityfocuscom/bid/25094/info Bandersnatch is prone to multiple input-validation vulnerabilities because the application fails to sanitize user-supplied input These issues include multiple SQL-injections vulnerabilities and an HTML-injection vulnerability A successful exploit may allow an attacker to steal cookie-based aut ...