CVE-2007-0695
Last modified
CVE-2007-0695 is a vulnerability of currently unknown severity. Multiple SQL injection vulnerabilities in Free LAN In(tra|ter)net Portal (FLIP) before 1.0-RC3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: some sources mention the escape_sqlData, implode_sql, and implode_sqlIn functions, but these are protection schemes, not the vulnerable functions.. EPSS estimates a 1.10% chance of exploitation in the next 30 days.
Description
Multiple SQL injection vulnerabilities in Free LAN In(tra|ter)net Portal (FLIP) before 1.0-RC3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: some sources mention the escape_sqlData, implode_sql, and implode_sqlIn functions, but these are protection schemes, not the vulnerable functions.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Free Lan Intra Internet Portal | Free Lan Intra Internet Portal | <= 1.0_rc2 |
| Free Lan Intra Internet Portal | Free Lan Intra Internet Portal | 0.9.0.730 |
| Free Lan Intra Internet Portal | Free Lan Intra Internet Portal | 0.9.0.1029 |
| Free Lan Intra Internet Portal | Free Lan Intra Internet Portal | 1.0_rc1 |
References
- http://www.vupen.com/english/advisories/2007/0454Vendor Advisory
- http://www.vupen.com/english/advisories/2007/0454Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-0695?
How severe is CVE-2007-0695?
How do I fix CVE-2007-0695?
Are you affected by CVE-2007-0695?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
