Vulnerabilities > CVE-2007-1909 - SQL Injection vulnerability in Battle.net Clan Script Login.PHP

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
ryan-haudenschilt
exploit available

Summary

SQL injection vulnerability in login.php in Ryan Haudenschilt Battle.net Clan Script for PHP 1.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) user or (2) pass parameter.

Vulnerable Configurations

Part Description Count
Application
Ryan_Haudenschilt
1

Exploit-Db

descriptionBattle.net Clan Script for PHP 1.5.1 Remote SQL Injection Vulnerability. CVE-2007-1909. Webapps exploit for php platform
fileexploits/php/webapps/3691.txt
idEDB-ID:3691
last seen2016-01-31
modified2007-04-09
platformphp
port
published2007-04-09
reporterh a c k e r _ X
sourcehttps://www.exploit-db.com/download/3691/
titleBattle.net Clan Script for PHP 1.5.1 - Remote SQL Injection Vulnerability
typewebapps