Vulnerabilities > CVE-2007-3814 - SQL Injection vulnerability in Mkportal 1.1.1

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
mkportal
exploit available

Summary

Multiple SQL injection vulnerabilities in MKPortal 1.1.1 allow remote attackers to execute arbitrary SQL commands via (1) the idurlo field in the delete_urlo function in (a) index.php in the urlobox module; the iden field in the (2) update_file and (3) del_file functions in (b) index.php in the reviews module; the (4) idnews field in the delete_news function and the (5) idcomm field in the del_comment function in (c) index.php in the news module; the (6) idcomm field in the delete_comments function in (d) index.php in the gallery module; the iden field in the (7) edit_file, (8) update_file, and (9) del_file functions in index.php in the gallery module; the (10) ide and (11) cat fields in the slide_update function in index.php in the gallery module; the iden field in the (12) update_file and (13) del_file functions in (d) index.php in the downloads module; and other unspecified vectors.

Vulnerable Configurations

Part Description Count
Application
Mkportal
1

Exploit-Db

descriptionMkPortal <= 1.1.1 reviews / gallery modules SQL Injection Exploit. CVE-2007-3814. Webapps exploit for php platform
fileexploits/php/webapps/4179.php
idEDB-ID:4179
last seen2016-01-31
modified2007-07-12
platformphp
port
published2007-07-12
reporterColoss
sourcehttps://www.exploit-db.com/download/4179/
titleMkPortal <= 1.1.1 reviews / gallery modules SQL Injection Exploit
typewebapps