7.5
CVSSv2

CVE-2007-3937

Published: 21/07/2007 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in A-shop 0.70 and previous versions allow remote malicious users to execute arbitrary SQL commands via unspecified vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

a-shop a-shop

Exploits

A-shop <=070 Multiple vulnerabilities Found Bug: Timq site:private-nodenet email:timq@hushmailcom Vendor:wwwrammdevcom/ashop/ PoC: sitecom/admin/filebrowserasp?folder=products&delfiles=[del any file on server] It is possible to delete not only the files in the folders listed, but also ouside its directory Al ...