Vulnerabilities > CVE-2007-1806 - SQL Injection vulnerability in RED Mexico Rm+Soft Gallery 1.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
red-mexico
exploit available

Summary

SQL injection vulnerability in categos.php in the RM+Soft Gallery (rmgallery) 1.0 module for Xoops allows remote attackers to execute arbitrary SQL commands via the idcat parameter.

Vulnerable Configurations

Part Description Count
Application
Red_Mexico
1

Exploit-Db

descriptionXOOPS Module RM+Soft Gallery 1.0 BLIND SQL Injection Exploit. CVE-2007-1806. Webapps exploit for php platform
fileexploits/php/webapps/3633.html
idEDB-ID:3633
last seen2016-01-31
modified2007-04-01
platformphp
port
published2007-04-01
reporterajann
sourcehttps://www.exploit-db.com/download/3633/
titleXOOPS Module RM+Soft Gallery 1.0 - Blind SQL Injection Exploit
typewebapps