7.5
CVSSv2

CVE-2007-5430

Published: 12/10/2007 Updated: 15/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 765
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Stride 1.0 allow remote malicious users to execute arbitrary SQL commands via (1) the p parameter to main.php in the Content Management System, (2) the id parameter in a sto cmd action to shop.php in the Merchant subsystem, or the (3) course or (4) provider parameter to detail.php in the Courses subsystem.

Vulnerable Product Search on Vulmon Subscribe to Product

scottmanktelow stride cms 1.0

Exploits

source: wwwsecurityfocuscom/bid/26041/info Scott Manktelow Design Stride 10 Content Management System is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query Exploiting this issue could allow an attacker to compromise the application, access or modify data, ...
source: wwwsecurityfocuscom/bid/26046/info Scott Manktelow Design Stride 10 Merchant is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit laten ...
source: wwwsecurityfocuscom/bid/26036/info Stride 10 Courses is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilit ...