Vulnerabilities > CVE-2007-1438 - SQL Injection vulnerability in X-Ice News System 1.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
x-ice
exploit available

Summary

SQL injection vulnerability in devami.asp in X-Ice News System 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

Vulnerable Configurations

Part Description Count
Application
X-Ice
1

Exploit-Db

descriptionX-ice News System 1.0 (devami.asp id) SQL Injection Vulnerability. CVE-2007-1438,CVE-2007-1570. Webapps exploit for asp platform
fileexploits/asp/webapps/3469.txt
idEDB-ID:3469
last seen2016-01-31
modified2007-03-13
platformasp
port
published2007-03-13
reporterCyberGhost
sourcehttps://www.exploit-db.com/download/3469/
titleX-ice News System 1.0 devami.asp id SQL Injection Vulnerability
typewebapps