7.5
CVSSv2

CVE-2007-4603

Published: 31/08/2007 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in index.php in ACG News 1.0 allow remote malicious users to execute arbitrary SQL commands via (1) the aid parameter in a showarticle action or (2) the catid parameter in a showcat action.

Vulnerable Product Search on Vulmon Subscribe to Product

altercoder acg news 1.0

Exploits

source: wwwsecurityfocuscom/bid/25466/info ACG News is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in SQL queries Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the ...
ACG News SQL Injection Software: ACG News 10 Vendor link: wwwaltercodercom Vendor Demo link: acgnewsuwhu/indexphp Attack: SQL Injection Original Advisory: 14houseblogspotcom/2007/08/acg-news-sql-injectionhtml Discovered by: David Sopas Ferreira aka SmOk3 < smok3f00 at gmailcom > SQL Injection ------------- ...