Vulnerabilities > CVE-2007-1172 - Unspecified vulnerability in Nukescripts Nukesentinel 2.5.05
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN nukescripts
exploit available
Summary
SQL injection vulnerability in nukesentinel.php in NukeSentinel 2.5.05, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header, aka the "File Disclosure Exploit."
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | NukeSentinel 2.5.05 (nukesentinel.php) File Disclosure Exploit. CVE-2007-1172,CVE-2007-1493. Webapps exploit for php platform |
file | exploits/php/webapps/3338.php |
id | EDB-ID:3338 |
last seen | 2016-01-31 |
modified | 2007-02-20 |
platform | php |
port | |
published | 2007-02-20 |
reporter | DarkFig |
source | https://www.exploit-db.com/download/3338/ |
title | NukeSentinel 2.5.05 - nukesentinel.php File Disclosure Exploit |
type | webapps |
References
- http://attrition.org/pipermail/vim/2007-March/001429.html
- http://attrition.org/pipermail/vim/2007-March/001429.html
- http://secunia.com/advisories/24221
- http://secunia.com/advisories/24221
- http://securityreason.com/securityalert/2341
- http://securityreason.com/securityalert/2341
- http://www.securityfocus.com/archive/1/460599/100/0/threaded
- http://www.securityfocus.com/archive/1/460599/100/0/threaded
- https://www.exploit-db.com/exploits/3338
- https://www.exploit-db.com/exploits/3338