Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2007-6366

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2007-6366
Last Modified 05 Sep 2009 01:12:06
Published 14 Dec 2007 08:46:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2007-6366

Summary

Multiple SQL injection vulnerabilities in SineCMS 2.3.4 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to mods/Calendar/index.php, accessed through a Calendar info action to mods.php; the id parameter to admin/mods_adm.php in a (2) Guestbook modifica or (3) Calendar modify action; or the (4) mese or (5) anno parameter to admin/mods_adm.php in a Calendar action. NOTE: the component for vectors 2 through 5 might be limited to administrators.

Vulnerable Systems

Application

  • Sinecms 2.3.4


References

XF - sinecms-mods-sql-injection(38895)

BUGTRAQ - 20071218 Re: SineCMS <= 2.3.4 Calendar SQL Injection 'n something else..

BUGTRAQ - 20071205 SineCMS <= 2.3.4 Calendar SQL Injection 'n something else..

MILW0RM - 4693

SECUNIA - 27949

SREASON - 3444


Last Updated: 27 May 2016 10:46:28