Vulnerabilities > CVE-2007-1550 - SQL-Injection vulnerability in PHPX
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Multiple SQL injection vulnerabilities in phpx 3.5.15 allow remote attackers to execute arbitrary SQL commands via the (1) image_id or (2) cat_id parameter to (a) gallery.php; the (3) news_id parameter to (b) news.php or (c) print.php; (4) the news_cat_id parameter to news.php; the (5) cat_id, (6) topic_id, or (7) post_id parameter to (d) forums.php; or (8) the user_id parameter to (e) users.php.
Exploit-Db
description PHPX 3.5.15/3.5.16 forums.php Multiple Parameter SQL Injection. CVE-2007-1550. Webapps exploit for php platform id EDB-ID:29757 last seen 2016-02-03 modified 2007-03-19 published 2007-03-19 reporter laurent gaffie source https://www.exploit-db.com/download/29757/ title PHPX 3.5.15/3.5.16 forums.php Multiple Parameter SQL Injection description PHPX 3.5.15/3.5.16 news.php Multiple Parameter SQL Injection. CVE-2007-1550. Webapps exploit for php platform id EDB-ID:29759 last seen 2016-02-03 modified 2007-03-19 published 2007-03-19 reporter laurent gaffie source https://www.exploit-db.com/download/29759/ title PHPX 3.5.15/3.5.16 news.php Multiple Parameter SQL Injection description PHPX 3.5.15/3.5.16 users.php user_id Parameter SQL Injection. CVE-2007-1550. Webapps exploit for php platform id EDB-ID:29758 last seen 2016-02-03 modified 2007-03-19 published 2007-03-19 reporter laurent gaffie source https://www.exploit-db.com/download/29758/ title PHPX 3.5.15/3.5.16 users.php user_id Parameter SQL Injection description PHPX 3.5.15/3.5.16 gallery.php Multiple Parameter SQL Injection. CVE-2007-1550. Webapps exploit for php platform id EDB-ID:29760 last seen 2016-02-03 modified 2007-03-19 published 2007-03-19 reporter laurent gaffie source https://www.exploit-db.com/download/29760/ title PHPX 3.5.15/3.5.16 gallery.php Multiple Parameter SQL Injection description PHPX 3.5.15/3.5.16 print.php news_id Parameter SQL Injection. CVE-2007-1550 . Webapps exploit for php platform id EDB-ID:29756 last seen 2016-02-03 modified 2007-03-19 published 2007-03-19 reporter laurent gaffie source https://www.exploit-db.com/download/29756/ title PHPX 3.5.15/3.5.16 print.php news_id Parameter SQL Injection
References
- http://osvdb.org/34414
- http://osvdb.org/34415
- http://osvdb.org/34416
- http://osvdb.org/34417
- http://osvdb.org/34418
- http://secunia.com/advisories/24565
- http://securityreason.com/securityalert/2457
- http://www.securityfocus.com/archive/1/463192/100/0/threaded
- http://www.securityfocus.com/bid/23033
- http://www.vupen.com/english/advisories/2007/1087
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33155