7.5
CVSSv2

CVE-2007-6128

Published: 26/11/2007 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in events.php in WorkingOnWeb 2.0.1400 allows remote malicious users to execute arbitrary SQL commands via the idevent parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

flor de utopia workingonweb 2.0.1400

Exploits

WorkingOnWeb 201400 Remote SQL Injection d0rk: Powered by WorkingOnWeb 201400 bug found by ka0x - DOM TEAM contact: ka0x01[!]gmailcom we: ka0x, an0de, xarnuz, s0cratex, Hendrix #from spain 1: <? 2: $query = "SELECT cnf_shortname, cnf_name, cnf_begindate, cnf_enddate, cnf_city, cnf_email, cnf_url, cnf_imgpath, cnf_country " 3: ...