Vulnerabilities > CVE-2007-4112 - Unspecified vulnerability in Advanced Webhost Billing System Advanced Webhost Billing System
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Multiple SQL injection vulnerabilities in Advanced Webhost Billing System (AWBS) before 2.6.0, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: this can be leveraged for XSS attacks that "bypass AWBS's anti-XSS input validation."
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- http://osvdb.org/37257
- http://osvdb.org/37257
- http://secunia.com/advisories/26214
- http://secunia.com/advisories/26214
- http://www.justinsamuel.com/2007/06/10/awbs-magic_quotes_gpc-off-sql-injection-and-xss-vulnerabilities/
- http://www.justinsamuel.com/2007/06/10/awbs-magic_quotes_gpc-off-sql-injection-and-xss-vulnerabilities/
- http://www.securityfocus.com/bid/25089
- http://www.securityfocus.com/bid/25089
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46160
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46160