Vulnerabilities > CVE-2007-3290 - Input Validation vulnerability in LiveCMS

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
livecms
critical
exploit available

Summary

categoria.php in LiveCMS 3.4 and earlier allows remote attackers to obtain sensitive information via a ' (quote) character in the cid parameter, which reveals the path in a forced SQL error message. More information about this CVE can be found at: http://secunia.com/advisories/25744/

Exploit-Db

descriptionLiveCMS <= 3.4 (categoria.php cid) Remote SQL Injection Exploit. CVE-2007-3290,CVE-2007-3291,CVE-2007-3292,CVE-2007-3293. Webapps exploit for php platform
fileexploits/php/webapps/4082.pl
idEDB-ID:4082
last seen2016-01-31
modified2007-06-20
platformphp
port
published2007-06-20
reporterg00ns
sourcehttps://www.exploit-db.com/download/4082/
titleLiveCMS <= 3.4 categoria.php cid Remote SQL Injection Exploit
typewebapps