Vulnerabilities > CVE-2007-4069 - SQL Injection vulnerability in Index Script Index Script 2.8

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
index-script
exploit available

Summary

SQL injection vulnerability in show_cat.php in IndexScript 2.8 and earlier allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. http://www.frsirt.com/english/advisories/2007/2696 Vendor has released a patch for this vulnerability: http://www.indexscript.com/forum/showthread.php?t=2266

Vulnerable Configurations

Part Description Count
Application
Index_Script
1

Exploit-Db

descriptionIndexScript <= 2.8 (show_cat.php cat_id) SQL Injection Vulnerability. CVE-2007-4069. Webapps exploit for php platform
fileexploits/php/webapps/4225.txt
idEDB-ID:4225
last seen2016-01-31
modified2007-07-25
platformphp
port
published2007-07-25
reporterxssvgamer
sourcehttps://www.exploit-db.com/download/4225/
titleIndexScript <= 2.8 show_cat.php cat_id SQL Injection Vulnerability
typewebapps