Vulnerabilities > CVE-2007-3013 - SQL Injection vulnerability in ActiveWeb Contentserver Picture_Real_Edit.ASP

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
activeweb
exploit available

Summary

SQL injection vulnerability in activeWeb contentserver before 5.6.2964 allows remote authenticated users with edit permission to execute arbitrary SQL commands via the id parameter to admin/picture/picture_real_edit.asp, and probably other unspecified vectors.

Vulnerable Configurations

Part Description Count
Application
Activeweb
1

Exploit-Db

descriptionActiveWeb Contentserver 5.6.2929 Picture_Real_Edit.ASP SQL Injection Vulnerability. CVE-2007-3013 . Webapps exploit for asp platform
idEDB-ID:30296
last seen2016-02-03
modified2007-07-13
published2007-07-13
reporterRedTeam Pentesting
sourcehttps://www.exploit-db.com/download/30296/
titleActiveWeb Contentserver 5.6.2929 Picture_Real_Edit.ASP SQL Injection Vulnerability

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/57734/rt-sa-2007-004.txt
idPACKETSTORM:57734
last seen2016-12-05
published2007-07-13
reporterredteam-pentesting.de
sourcehttps://packetstormsecurity.com/files/57734/rt-sa-2007-004.txt.html
titlert-sa-2007-004.txt