CVE-2007-4210
Last modified
CVE-2007-4210 is a vulnerability of currently unknown severity. Multiple SQL injection vulnerabilities in module.php in LANAI (la-nai) CMS 1.2.14 allow remote attackers to execute arbitrary SQL commands via (1) the mid parameter in an faqviewgroup action in the FAQ Modules, (2) the cid parameter in the EZSHOPINGCART Modules, or (3) the gid parameter in a view action in the GALLERY Modules.. EPSS estimates a 2.94% chance of exploitation in the next 30 days.
Description
Multiple SQL injection vulnerabilities in module.php in LANAI (la-nai) CMS 1.2.14 allow remote attackers to execute arbitrary SQL commands via (1) the mid parameter in an faqviewgroup action in the FAQ Modules, (2) the cid parameter in the EZSHOPINGCART Modules, or (3) the gid parameter in a view action in the GALLERY Modules.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redline Software | Lanai Cms | 1.2.14 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-4210?
How severe is CVE-2007-4210?
How do I fix CVE-2007-4210?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-4204Hitachi Groupmax Collaboration - Schedule, as used in Groupm…
- CVE-2007-4205XHA (Linux-HA) on the BlueCat Networks Adonis DNS/DHCP Appli…
- CVE-2007-4206Kaspersky Anti-Spam 3.0 MP1 before Critical Fix 2 (3.0.278.4…
- CVE-2007-4207SQL injection vulnerability in admin_console/index.asp in Ga…
- CVE-2007-4208SQL injection vulnerability in default.asp in Next Gen Portf…
- CVE-2007-4209SQL injection vulnerability in Recherche.php in Aceboard for…
- CVE-2007-4211The ACL plugin in Dovecot before 1.0.3 allows remote authent…
- CVE-2007-4212Multiple cross-site scripting (XSS) vulnerabilities in the S…
- CVE-2007-4213Palm OS on Treo 650, 680, 700p, and 755p Smart phones allows…
- CVE-2007-4216vsdatant.sys 6.5.737.0 in Check Point Zone Labs ZoneAlarm be…
- CVE-2007-4217Stack-based buffer overflow in the domacro function in ftp i…
- CVE-2007-4218Multiple buffer overflows in the ServerProtect service (Spnt…
Are you affected by CVE-2007-4210?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
