CVE-2007-1920
UnknownEPSS 1.18%
Last modified
CVE-2007-1920 is a vulnerability of currently unknown severity. SQL injection vulnerability in index.php in the aktualnosci module in SmodBIP 1.06 and earlier allows remote attackers to execute arbitrary SQL commands via the zoom parameter, possibly related to home.php.. EPSS estimates a 1.18% chance of exploitation in the next 30 days.
Description
SQL injection vulnerability in index.php in the aktualnosci module in SmodBIP 1.06 and earlier allows remote attackers to execute arbitrary SQL commands via the zoom parameter, possibly related to home.php.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Smodbip | Smodbip | <= 1.06 |
References
- http://secunia.com/advisories/24802Vendor Advisory
- http://www.securityfocus.com/bid/23356Exploit, Vendor Advisory
- http://www.vupen.com/english/advisories/2007/1298Vendor Advisory
- http://secunia.com/advisories/24802Vendor Advisory
- http://www.securityfocus.com/bid/23356Exploit, Vendor Advisory
- http://www.vupen.com/english/advisories/2007/1298Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-1920?
SQL injection vulnerability in index.php in the aktualnosci module in SmodBIP 1.06 and earlier allows remote attackers to execute arbitrary SQL commands via the zoom parameter, possibly related to home.php.
How severe is CVE-2007-1920?
Severity scoring for CVE-2007-1920 is pending analysis. The EPSS model estimates a 1.18% probability of exploitation in the next 30 days.
How do I fix CVE-2007-1920?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-1914The RFC_START_PROGRAM function in the SAP RFC Library 6.40 a…
- CVE-2007-1915Buffer overflow in the RFC_START_PROGRAM function in the SAP…
- CVE-2007-1916Buffer overflow in the RFC_START_GUI function in the SAP RFC…
- CVE-2007-1917Buffer overflow in the SYSTEM_CREATE_INSTANCE function in th…
- CVE-2007-1918The RFC_SET_REG_SERVER_PROPERTY function in the SAP RFC Libr…
- CVE-2007-1919Cross-site scripting (XSS) vulnerability in index.php in Ari…
- CVE-2007-1921LIBSNDFILE.DLL, as used by AOL Nullsoft Winamp 5.33 and poss…
- CVE-2007-1922The Impulse Tracker (IT) and ScreamTracker 3 (S3M) modules i…
- CVE-2007-1923(1) LedgerSMB and (2) DWS Systems SQL-Ledger implement acces…
- CVE-2007-1924Multiple PHP remote file inclusion vulnerabilities in phpCon…
- CVE-2007-1925The borrado function in modules/Your_Account/index.php in Tr…
- CVE-2007-1926Cross-site scripting (XSS) vulnerability in JBMC Software Di…
Are you affected by CVE-2007-1920?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
