Vulnerabilities > CVE-2007-2662 - SQL Injection vulnerability in Efestech Haber Efestech Haber 5.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
efestech-haber
exploit available

Summary

SQL injection vulnerability in EfesTECH Haber 5.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to the top-level URI.

Vulnerable Configurations

Part Description Count
Application
Efestech_Haber
1

Exploit-Db

descriptionEfesTECH Haber 5.0 (id) Remote SQL Injection Vulnerability. CVE-2007-2662. Webapps exploit for php platform
fileexploits/php/webapps/3911.txt
idEDB-ID:3911
last seen2016-01-31
modified2007-05-14
platformphp
port
published2007-05-14
reporterCyberGhost
sourcehttps://www.exploit-db.com/download/3911/
titleEfesTECH Haber 5.0 id Remote SQL Injection Vulnerability
typewebapps