Vulnerabilities > CVE-2007-2866 - Unspecified vulnerability in PHPecho CMS PHPecho CMS
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Multiple SQL injection vulnerabilities in modules/admin/modules/gallery.php in PHPEcho CMS 2.0-rc1 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter and possibly other parameters. NOTE: some of these details are obtained from third party information.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- http://osvdb.org/38053
- http://osvdb.org/38053
- http://sourceforge.net/project/shownotes.php?release_id=495821&group_id=186100
- http://sourceforge.net/project/shownotes.php?release_id=495821&group_id=186100
- http://www.vupen.com/english/advisories/2007/1937
- http://www.vupen.com/english/advisories/2007/1937