7.5
CVSSv2

CVE-2007-4804

Published: 11/09/2007 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in AuraCMS 1.5rc allow remote malicious users to execute arbitrary SQL commands via the id parameter in (1) hal.php, (2) cetak.php, (3) lihat.php, (4) pesan.php, and (5) teman.php, different vectors than CVE-2007-4171. NOTE: the scripts may be accessed through requests to the product's top-level default URI, using the pilih parameter, in some circumstances.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

auracms auracms 1.5_rc

Exploits

######################################################################## # AuraCMS version 15rc - Multiple Remote SQL Injection Vulnerabilities # Vendor : wwwauracmsorg/ # Ditemukan oleh : k1tk4t - k1tk4t[4t]newhackorg # Lokasi : Indonesia -- #newhack[dot]org @ ircdalnet ######################################### ...