Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2007-4171

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2007-4171
Last Modified 15 Nov 2008 01:56:06
Published 07 Aug 2007 06:17:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2007-4171

Summary

SQL injection vulnerability in komentar.php in the Forum Module for auraCMS (Modul Forum Sederhana) allows remote attackers to execute arbitrary SQL commands via the id parameter to the default URI. NOTE: some of these details are obtained from third party information.

Vulnerable Systems

Application

  • Auracms Modul Forum Sederhana


References

SECUNIA - 26332

OSVDB - 36432

MILW0RM - 4254

XF - auracms-komentar-sql-injection(35814)

BID - 25202

BUGTRAQ - 20070805 AuraCMS [Forum Module] - Remote SQL Injection


Last Updated: 27 May 2016 10:45:46