Vulnerabilities > CVE-2007-0316 - SQL Injection vulnerability in All In One Control Panel

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
all-in-one-control-panel
exploit available

Summary

Multiple SQL injection vulnerabilities in All In One Control Panel (AIOCP) 1.3.010 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) xuser_name parameter to shared/code/cp_authorization.php, and the (2) did parameter to public/code/cp_downloads.php, different vectors than CVE-2007-0223.

Vulnerable Configurations

Part Description Count
Application
All_In_One_Control_Panel
1

Exploit-Db

descriptionAll In One Control Panel 1.3.x cp_downloads.php did Parameter SQL Injection. CVE-2007-0316. Webapps exploit for php platform
idEDB-ID:29451
last seen2016-02-03
modified2007-01-12
published2007-01-12
reporterColoss
sourcehttps://www.exploit-db.com/download/29451/
titleAll In One Control Panel 1.3.x cp_downloads.php did Parameter SQL Injection