Vulnerabilities > CVE-2007-1979 - SQL Injection vulnerability in Bluemoon Inc. PopnupBlog XOOPS Module

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
xoops
exploit available

Summary

SQL injection vulnerability in index.php in the PopnupBlog 2.52 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the postid parameter, possibly involving the get_blogid_from_postid function in class/PopnupBlogUtils.php. NOTE: later versions such as 3.03 and 3.05 might also be affected.

Vulnerable Configurations

Part Description Count
Application
Xoops
1

Exploit-Db

descriptionXOOPS Module PopnupBlog <= 2.52 (postid) BLIND SQL Injection Exploit. CVE-2007-1979. Webapps exploit for php platform
fileexploits/php/webapps/3655.html
idEDB-ID:3655
last seen2016-01-31
modified2007-04-03
platformphp
port
published2007-04-03
reporterajann
sourcehttps://www.exploit-db.com/download/3655/
titleXOOPS Module PopnupBlog <= 2.52 postid BLIND SQL Injection Exploit
typewebapps