7.5
CVSSv2

CVE-2007-6380

Published: 15/12/2007 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 785
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in e-Xoops (exoops) 1.08, and 1.05 Rev 1 through 3, allow remote malicious users to execute arbitrary SQL commands via the (1) lid parameter to (a) mylinks/ratelink.php, (b) adresses/ratefile.php, (c) mydownloads/ratefile.php, (d) mysections/ratefile.php, and (e) myalbum/ratephoto.php in modules/; the (2) bid parameter to (f) modules/banners/click.php; and the (3) gid parameter to (g) modules/arcade/index.php in a show_stats and play_game action, related issues to CVE-2007-5104 and CVE-2007-6266.

Vulnerable Product Search on Vulmon Subscribe to Product

e-xoops e-xoops 1.05_rev1

e-xoops e-xoops 1.05_rev3

e-xoops e-xoops 1.05_rev2

e-xoops e-xoops 1.08

Exploits

source: wwwsecurityfocuscom/bid/26796/info E-Xoops is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in th ...
source: wwwsecurityfocuscom/bid/26796/info E-Xoops is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the ...
source: wwwsecurityfocuscom/bid/26796/info E-Xoops is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabiliti ...
source: wwwsecurityfocuscom/bid/26796/info E-Xoops is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities ...
source: wwwsecurityfocuscom/bid/26796/info E-Xoops is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities i ...
source: wwwsecurityfocuscom/bid/26796/info E-Xoops is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in ...
source: wwwsecurityfocuscom/bid/26796/info E-Xoops is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabili ...