Vulnerabilities > CVE-2007-0663 - SQL-Injection vulnerability in Eclectic Designs Cascadianfaq 4.1

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
eclectic-designs
exploit available

Summary

SQL injection vulnerability in index.php in Eclectic Designs CascadianFAQ 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the qid parameter, a different vector than CVE-2007-0631. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

Vulnerable Configurations

Part Description Count
Application
Eclectic_Designs
2

Exploit-Db

descriptionCascadianFAQ <= 4.1 (index.php) Remote SQL Injection Vulnerability. CVE-2007-0631,CVE-2007-0663. Webapps exploit for php platform
fileexploits/php/webapps/3227.txt
idEDB-ID:3227
last seen2016-01-31
modified2007-01-30
platformphp
port
published2007-01-30
reporterajann
sourcehttps://www.exploit-db.com/download/3227/
titleCascadianFAQ <= 4.1 index.php Remote SQL Injection Vulnerability
typewebapps