Vulnerabilities > CVE-2007-3354 - Input Validation vulnerability in Scriptdevelopers.Net Netclassifieds 1.0.1/1.5.1/1.9.6.3

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
scriptdevelopers-net
exploit available

Summary

Multiple SQL injection vulnerabilities in NetClassifieds Premium Edition allow remote attackers to execute arbitrary SQL commands via the s_user_id parameter to ViewCat.php and other unspecified vectors. NOTE: the CatID/ViewCat.php, CatID/gallery.php, and ItemNum/ViewItem.php vectors are already covered by CVE-2005-3978.

Exploit-Db

descriptionNetClassifieds 1.9.7 Multiple Input Validation Vulnerabilities. CVE-2007-3354. Webapps exploit for php platform
idEDB-ID:30223
last seen2016-02-03
modified2007-06-21
published2007-06-21
reporterlaurent gaffie
sourcehttps://www.exploit-db.com/download/30223/
titleNetClassifieds <= 1.9.7 - Multiple Input Validation Vulnerabilities