Vulnerabilities > CVE-2007-2792 - Unspecified vulnerability in COM Yanc COM Yanc 1.4Beta
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
SQL injection vulnerability in the Yet another Newsletter Component (aka YaNC or com_yanc) component before 1.5 beta 3 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter to index.php. NOTE: some of these details are obtained from third party information.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description Mambo com_yanc 1.4 beta (id) Remote SQL Injection Vulnerability. CVE-2007-2792. Webapps exploit for php platform file exploits/php/webapps/3944.txt id EDB-ID:3944 last seen 2016-01-31 modified 2007-05-17 platform php port published 2007-05-17 reporter Mehmet Ince source https://www.exploit-db.com/download/3944/ title Mambo com_yanc 1.4 beta id Remote SQL Injection Vulnerability type webapps description Joomla Component com_yanc SQL Injection Vulnerability. Webapps exploit for php platform file exploits/php/webapps/11603.txt id EDB-ID:11603 last seen 2016-02-01 modified 2010-02-28 platform php port published 2010-02-28 reporter snakespc source https://www.exploit-db.com/download/11603/ title Joomla Component com_yanc SQL Injection Vulnerability type webapps
Nessus
NASL family | CGI abuses |
NASL id | YANC_LISTID_SQL_INJECTION.NASL |
description | The version of the YaNC component for Joomla! and Mambo running on the remote host is affected by a SQL injection vulnerability in the components/com_yanc/yanc.html.php script due to improper sanitization of user-supplied input to the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 25243 |
published | 2007-05-17 |
reporter | This script is Copyright (C) 2007-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/25243 |
title | YaNC Component for Joomla! 'listid' Parameter SQLi |
code |
|
References
- http://osvdb.org/37948
- http://osvdb.org/37948
- http://osvdb.org/62620
- http://osvdb.org/62620
- http://packetstormsecurity.org/0806-exploits/joomlayanc-sql.txt
- http://packetstormsecurity.org/0806-exploits/joomlayanc-sql.txt
- http://secunia.com/advisories/38780
- http://secunia.com/advisories/38780
- http://www.exploit-db.com/exploits/11603
- http://www.exploit-db.com/exploits/11603
- http://www.securityfocus.com/bid/24030
- http://www.securityfocus.com/bid/24030
- http://www.securityfocus.com/bid/38454
- http://www.securityfocus.com/bid/38454
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56585
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56585
- https://www.exploit-db.com/exploits/3944
- https://www.exploit-db.com/exploits/3944