Vulnerabilities > CVE-2007-0693 - SQL Injection vulnerability in Dgnews 1.5.1/2.1

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
dian-gemilang
exploit available

Summary

SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a newslist action. NOTE: this issue can produce resultant cross-site scripting (XSS).

Vulnerable Configurations

Part Description Count
Application
Dian_Gemilang
2

Exploit-Db

  • descriptionDGNews 1.5.1/2.1 News.PHP SQL Injection Vulnerability. CVE-2007-0693. Webapps exploit for php platform
    idEDB-ID:30095
    last seen2016-02-03
    modified2007-05-28
    published2007-05-28
    reporterJesper Jurcenoks
    sourcehttps://www.exploit-db.com/download/30095/
    titleDGNews 1.5.1/2.1 News.PHP SQL Injection Vulnerability
  • descriptionDGNews 2.1 NewsID Parameter SQL Injection Vulnerability. CVE-2007-0693. Webapps exploit for php platform
    idEDB-ID:30099
    last seen2016-02-03
    modified2007-05-28
    published2007-05-28
    reporterlaurent gaffie
    sourcehttps://www.exploit-db.com/download/30099/
    titleDGNews 2.1 NewsID Parameter SQL Injection Vulnerability