Vulnerabilities > CVE-2007-1363 - Unspecified vulnerability in Dropafew
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN dropafew
exploit available
Summary
Multiple SQL injection vulnerabilities in DropAFew before 0.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in the delete action in (a) search.php or (b) search-pda.php, or the (2) calories parameter in a save action in editlogcal.php.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description DropAFew 0.2 search.php delete Action id Parameter SQL Injection. CVE-2007-1363. Webapps exploit for php platform id EDB-ID:29832 last seen 2016-02-03 modified 2007-04-10 published 2007-04-10 reporter Alexander Klink source https://www.exploit-db.com/download/29832/ title DropAFew 0.2 - search.php delete Action id Parameter SQL Injection description DropAFew 0.2 editlogcal.php save Action calories Parameter SQL Injection. CVE-2007-1363. Webapps exploit for php platform id EDB-ID:29833 last seen 2016-02-03 modified 2007-04-10 published 2007-04-10 reporter Alexander Klink source https://www.exploit-db.com/download/29833/ title DropAFew 0.2 editlogcal.php save Action calories Parameter SQL Injection
Packetstorm
data source | https://packetstormsecurity.com/files/download/55830/AKLINK-SA-2007-002.txt |
id | PACKETSTORM:55830 |
last seen | 2016-12-05 |
published | 2007-04-11 |
reporter | Alexander Klink |
source | https://packetstormsecurity.com/files/55830/AKLINK-SA-2007-002.txt.html |
title | AKLINK-SA-2007-002.txt |
References
- http://secunia.com/advisories/24861
- http://secunia.com/advisories/24861
- http://www.cynops.de/advisories/CVE-2007-1363.txt
- http://www.cynops.de/advisories/CVE-2007-1363.txt
- http://www.dropafew.com/sphpblog/comments.php?y=07&m=04&entry=entry070403-224437
- http://www.dropafew.com/sphpblog/comments.php?y=07&m=04&entry=entry070403-224437
- http://www.securityfocus.com/bid/23400
- http://www.securityfocus.com/bid/23400
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33560
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33560