Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2007-4171


Vulnerability Score 7.5 7.5
CVE Id CVE-2007-4171
Last Modified 15 Nov 2008 01:56:06
Published 07 Aug 2007 06:17:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE



SQL injection vulnerability in komentar.php in the Forum Module for auraCMS (Modul Forum Sederhana) allows remote attackers to execute arbitrary SQL commands via the id parameter to the default URI. NOTE: some of these details are obtained from third party information.

Vulnerable Systems


  • Auracms Modul Forum Sederhana


SECUNIA - 26332

OSVDB - 36432

MILW0RM - 4254

XF - auracms-komentar-sql-injection(35814)

BID - 25202

BUGTRAQ - 20070805 AuraCMS [Forum Module] - Remote SQL Injection

Last Updated: 27 May 2016 10:45:46