Vulnerabilities > CVE-2007-1363 - Unspecified vulnerability in Dropafew

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
dropafew
exploit available

Summary

Multiple SQL injection vulnerabilities in DropAFew before 0.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in the delete action in (a) search.php or (b) search-pda.php, or the (2) calories parameter in a save action in editlogcal.php.

Vulnerable Configurations

Part Description Count
Application
Dropafew
1

Exploit-Db

  • descriptionDropAFew 0.2 search.php delete Action id Parameter SQL Injection. CVE-2007-1363. Webapps exploit for php platform
    idEDB-ID:29832
    last seen2016-02-03
    modified2007-04-10
    published2007-04-10
    reporterAlexander Klink
    sourcehttps://www.exploit-db.com/download/29832/
    titleDropAFew 0.2 - search.php delete Action id Parameter SQL Injection
  • descriptionDropAFew 0.2 editlogcal.php save Action calories Parameter SQL Injection. CVE-2007-1363. Webapps exploit for php platform
    idEDB-ID:29833
    last seen2016-02-03
    modified2007-04-10
    published2007-04-10
    reporterAlexander Klink
    sourcehttps://www.exploit-db.com/download/29833/
    titleDropAFew 0.2 editlogcal.php save Action calories Parameter SQL Injection

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/55830/AKLINK-SA-2007-002.txt
idPACKETSTORM:55830
last seen2016-12-05
published2007-04-11
reporterAlexander Klink
sourcehttps://packetstormsecurity.com/files/55830/AKLINK-SA-2007-002.txt.html
titleAKLINK-SA-2007-002.txt