7.5
CVSSv2

CVE-2007-4210

Published: 08/08/2007 Updated: 29/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 770
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in module.php in LANAI (la-nai) CMS 1.2.14 allow remote malicious users to execute arbitrary SQL commands via (1) the mid parameter in an faqviewgroup action in the FAQ Modules, (2) the cid parameter in the EZSHOPINGCART Modules, or (3) the gid parameter in a view action in the GALLERY Modules.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redline software lanai cms 1.2.14

Exploits

source: wwwsecurityfocuscom/bid/25193/info LANAI CMS is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in th ...
source: wwwsecurityfocuscom/bid/25193/info LANAI CMS is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities i ...
source: wwwsecurityfocuscom/bid/25193/info LANAI CMS is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in ...
####################################################################### ########### newhack[dot]org ############ ######################################################################## # la-nai cms_v1214 - Remote SQL Injection # Vendor : wwwredlinesoftnet/modulephp?modname=content&cid=9 # Downl ...