Vulnerabilities > CVE-2007-4156 - Unspecified vulnerability in Woliocms

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
woliocms
exploit available

Summary

Multiple SQL injection vulnerabilities in wolioCMS allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to member.php in a page action, related to a SELECT statement in common.php; and the (2) loginid parameter (uid variable), and possibly the (3) pwd parameter, to admin/index.php.

Vulnerable Configurations

Part Description Count
Application
Woliocms
1

Exploit-Db

descriptionwolioCMS Auth Bypass / Remote SQL Injection Vulnerabilities. CVE-2007-4156. Webapps exploit for php platform
fileexploits/php/webapps/4246.txt
idEDB-ID:4246
last seen2016-01-31
modified2007-07-30
platformphp
port
published2007-07-30
reporterk1tk4t
sourcehttps://www.exploit-db.com/download/4246/
titlewolioCMS Auth Bypass / Remote SQL Injection Vulnerabilities
typewebapps