7.5
CVSSv2

CVE-2007-4552

Published: 28/08/2007 Updated: 15/11/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in index.php in Agares Media Arcadem 2.01 allows remote malicious users to execute arbitrary SQL commands via the blockpage parameter. NOTE: as of 20070827, the vendor has made conflicting statements regarding whether this issue exists or not.

Vulnerable Product Search on Vulmon Subscribe to Product

agares media arcadem 2.0.1

Exploits

Arcadem Remote File Inclusion Flaw / SQL Injection Software: Arcadem 201 Vendor link: agaresmediacom Attack: Remote File Inclusion / SQL Injection Original advisory: 14houseblogspotcom/2007/08/arcadem-rfi-sql-injection-flawshtml Discovered by: David Sopas Ferreira aka SmOk3 < smok3f00 at gmailcom > Google dork:"Powere ...