Vulnerabilities > CVE-2007-3905 - Unspecified vulnerability in Zoph
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN zoph
nessus
Summary
SQL injection vulnerability in Zoph before 0.7.0.1 might allow remote attackers to execute arbitrary SQL commands via the _order parameter to (1) photos.php and (2) edit_photos.php.
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DSA-1389.NASL |
description | It was discovered that zoph, a web-based photo management system, performs insufficient input sanitising, which allows SQL injection. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 27544 |
published | 2007-10-25 |
reporter | This script is Copyright (C) 2007-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/27544 |
title | Debian DSA-1389-2 : zoph - missing input sanitising |
code |
|
References
- http://secunia.com/advisories/26077
- http://secunia.com/advisories/26077
- http://secunia.com/advisories/27303
- http://secunia.com/advisories/27303
- http://sourceforge.net/project/shownotes.php?release_id=523104&group_id=69353
- http://sourceforge.net/project/shownotes.php?release_id=523104&group_id=69353
- http://www.debian.org/security/2007/dsa-1389
- http://www.debian.org/security/2007/dsa-1389
- http://www.securityfocus.com/bid/24933
- http://www.securityfocus.com/bid/24933
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35446
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35446