CVE-2007-6366
Last modified
CVE-2007-6366 is a vulnerability of currently unknown severity. Multiple SQL injection vulnerabilities in SineCMS 2.3.4 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to mods/Calendar/index.php, accessed through a Calendar info action to mods.php; the id parameter to admin/mods_adm.php in a (2) Guestbook modifica or (3) Calendar modify action; or the (4) mese or (5) anno parameter to admin/mods_adm.php in a Calendar action. NOTE: the component for vectors 2 through 5 might be limited to administrators.. EPSS estimates a 2.36% chance of exploitation in the next 30 days.
Description
Multiple SQL injection vulnerabilities in SineCMS 2.3.4 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to mods/Calendar/index.php, accessed through a Calendar info action to mods.php; the id parameter to admin/mods_adm.php in a (2) Guestbook modifica or (3) Calendar modify action; or the (4) mese or (5) anno parameter to admin/mods_adm.php in a Calendar action. NOTE: the component for vectors 2 through 5 might be limited to administrators.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sinecms | Sinecms | <= 2.3.4 |
References
- http://secunia.com/advisories/27949Vendor Advisory
- http://secunia.com/advisories/27949Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-6366?
How severe is CVE-2007-6366?
How do I fix CVE-2007-6366?
Are you affected by CVE-2007-6366?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
