Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2007-4163

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2007-4163
Last Modified 15 Nov 2008 01:56:04
Published 03 Aug 2007 05:17:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2007-4163

Summary

Multiple SQL injection vulnerabilities in IndexScript 2.7 and 2.8 before 20070726 allow remote attackers to execute arbitrary SQL commands via the (1) cat_id, (2) start_id, (3) row[parent_id], and (4) row[cat_id] parameters to unspecified components, related to use of these parameters within include/utils.php. NOTE: the show_cat.php cat_id vector is already covered by CVE-2007-4069.

Vulnerable Systems

Application

  • Index Script 2.7

  • Index Script 2.8


References

CONFIRM - http://www.indexscript.com/forum/showthread.php?t=2266

OSVDB - 46989


Last Updated: 27 May 2016 10:45:46