CVE-2007-3814
Last modified
CVE-2007-3814 is a vulnerability of currently unknown severity. Multiple SQL injection vulnerabilities in MKPortal 1.1.1 allow remote attackers to execute arbitrary SQL commands via (1) the idurlo field in the delete_urlo function in (a) index.php in the urlobox module; the iden field in the (2) update_file and (3) del_file functions in (b) index.php in the reviews module; the (4) idnews field in the delete_news function and the (5) idcomm field in the del_comment function in (c) index.php in the news module; the (6) idcomm field in the delete_comments function in (d) index.php in the gallery module; the iden field in the (7) edit_file, (8) update_file, and (9) del_file functions in index.php in the gallery module; the (10) ide and (11) cat fields in the slide_update function in index.php in the gallery module; the iden field in the (12) update_file and (13) del_file functions in (d) index.php in the downloads module; and other unspecified vectors.. EPSS estimates a 2.13% chance of exploitation in the next 30 days.
Description
Multiple SQL injection vulnerabilities in MKPortal 1.1.1 allow remote attackers to execute arbitrary SQL commands via (1) the idurlo field in the delete_urlo function in (a) index.php in the urlobox module; the iden field in the (2) update_file and (3) del_file functions in (b) index.php in the reviews module; the (4) idnews field in the delete_news function and the (5) idcomm field in the del_comment function in (c) index.php in the news module; the (6) idcomm field in the delete_comments function in (d) index.php in the gallery module; the iden field in the (7) edit_file, (8) update_file, and (9) del_file functions in index.php in the gallery module; the (10) ide and (11) cat fields in the slide_update function in index.php in the gallery module; the iden field in the (12) update_file and (13) del_file functions in (d) index.php in the downloads module; and other unspecified vectors.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mkportal | Mkportal | 1.1.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-3814?
How severe is CVE-2007-3814?
How do I fix CVE-2007-3814?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-3808SQL injection vulnerability in includes/search.php in paFile…
- CVE-2007-3809Multiple SQL injection vulnerabilities in Prozilla Directory…
- CVE-2007-3810SQL injection vulnerability in index.php in Realtor 747 allo…
- CVE-2007-3811Multiple SQL injection vulnerabilities in eSyndiCat allow re…
- CVE-2007-3812SQL injection vulnerability in forums.php in CMScout 1.23 an…
- CVE-2007-3813PHP remote file inclusion vulnerability in include/user.php …
- CVE-2007-3815Buffer overflow in pirs32.exe in Poslovni informator Republi…
- CVE-2007-3816JWIG might allow context-dependent attackers to cause a deni…7.5
- CVE-2007-3817Cross-site scripting (XSS) vulnerability in the LoginTobogga…
- CVE-2007-3818Cross-site scripting (XSS) vulnerability in the LoginTobogga…
- CVE-2007-3819Opera 9.21 allows remote attackers to spoof the data: URI sc…
- CVE-2007-3820konqueror/konq_combo.cc in Konqueror 3.5.7 allows remote att…
Are you affected by CVE-2007-3814?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
