Vulnerabilities > CVE-2007-4522 - SQL and HTML Injection vulnerability in Ripe Website Manager 0.8.4/0.8.9

047910
CVSS 6.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
ripe-website-manager
exploit available

Summary

Multiple SQL injection vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote authenticated users to execute arbitrary SQL commands via one or more of the following vectors: the (1) id parameter to (a) pages/delete_page.php, (b) navigation/delete_menu.php, and (c) navigation/delete_item.php in admin/; the (2) menu_id, (3) name, (3) page_id, and (4) url parameters in (d) admin/navigation/do_new_item.php; the (5) new_menuname parameter in (e) admin/navigation/do_new_nav.php; and (6) area1, name, and url parameters to (f) admin/pages/do_new_page.php. NOTE: some vectors might be reachable through the url and name parameters to (g) admin/navigation/new_nav_item.php. NOTE: the original disclosure does not precisely state which vectors are associated with SQL injection versus XSS.

Exploit-Db

descriptionRipe Website Manager 0.8.x pages/delete_page.php id Parameter SQL Injection. CVE-2007-4522. Webapps exploit for php platform
idEDB-ID:30518
last seen2016-02-03
modified2007-08-22
published2007-08-22
reporterNagendra Kumar G
sourcehttps://www.exploit-db.com/download/30518/
titleRipe Website Manager 0.8.x pages/delete_page.php id Parameter SQL Injection