Vulnerabilities > CVE-2007-4156 - Unspecified vulnerability in Woliocms
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN woliocms
exploit available
Summary
Multiple SQL injection vulnerabilities in wolioCMS allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to member.php in a page action, related to a SELECT statement in common.php; and the (2) loginid parameter (uid variable), and possibly the (3) pwd parameter, to admin/index.php.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | wolioCMS Auth Bypass / Remote SQL Injection Vulnerabilities. CVE-2007-4156. Webapps exploit for php platform |
file | exploits/php/webapps/4246.txt |
id | EDB-ID:4246 |
last seen | 2016-01-31 |
modified | 2007-07-30 |
platform | php |
port | |
published | 2007-07-30 |
reporter | k1tk4t |
source | https://www.exploit-db.com/download/4246/ |
title | wolioCMS Auth Bypass / Remote SQL Injection Vulnerabilities |
type | webapps |
References
- http://secunia.com/advisories/26270
- http://secunia.com/advisories/26270
- http://securityreason.com/securityalert/2956
- http://securityreason.com/securityalert/2956
- http://www.securityfocus.com/archive/1/475068/100/0/threaded
- http://www.securityfocus.com/archive/1/475068/100/0/threaded
- http://www.securityfocus.com/bid/25134
- http://www.securityfocus.com/bid/25134
- http://www.vupen.com/english/advisories/2007/2726
- http://www.vupen.com/english/advisories/2007/2726
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35678
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35678
- https://www.exploit-db.com/exploits/4246
- https://www.exploit-db.com/exploits/4246