Vulnerabilities > CVE-2007-2207 - SQL-Injection vulnerability in Ripe Website Manager

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
ripe-website-manager
exploit available

Summary

SQL injection vulnerability in contact/index.php in Ripe Website Manager 0.8.4 and earlier allows remote attackers to execute arbitrary SQL commands via the ripeformpost parameter.

Vulnerable Configurations

Part Description Count
Application
Ripe_Website_Manager
1

Exploit-Db

descriptionRipe Website Manager 0.8.4 contact/index.php ripeformpost Parameter SQL Injection. CVE-2007-2207. Webapps exploit for php platform
idEDB-ID:29877
last seen2016-02-03
modified2007-04-23
published2007-04-23
reporterJohn Martinelli
sourcehttps://www.exploit-db.com/download/29877/
titleRipe Website Manager 0.8.4 contact/index.php ripeformpost Parameter SQL Injection