CVE-2017-7290
Last modified
CVE-2017-7290 is a vulnerability of currently unknown severity. SQL injection vulnerability in XOOPS 2.5.7.2 and other versions before 2.5.8.1 allows remote authenticated administrators to execute arbitrary SQL commands via the url parameter to findusers.php. An example attack uses "into outfile" to create a backdoor program.. EPSS estimates a 2.30% chance of exploitation in the next 30 days.
Description
SQL injection vulnerability in XOOPS 2.5.7.2 and other versions before 2.5.8.1 allows remote authenticated administrators to execute arbitrary SQL commands via the url parameter to findusers.php. An example attack uses "into outfile" to create a backdoor program.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xoops | Xoops | 2.5.7.2 |
| Xoops | Xoops | 2.5.7.3 |
| Xoops | Xoops | 2.5.8.1 |
References
- http://www.securityfocus.com/bid/97230Third Party Advisory, VDB Entry
- https://gist.github.com/jk1986/3b304ac6b4ae52ae667bba380c2dce19Exploit, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/97230Third Party Advisory, VDB Entry
- https://gist.github.com/jk1986/3b304ac6b4ae52ae667bba380c2dce19Exploit, Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-7290?
How severe is CVE-2017-7290?
How do I fix CVE-2017-7290?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-7282An issue was discovered in Unitrends Enterprise Backup befor…
- CVE-2017-7283An authenticated user of Unitrends Enterprise Backup before …
- CVE-2017-7284An attacker that has hijacked a Unitrends Enterprise Backup …
- CVE-2017-7285A vulnerability in the network stack of MikroTik Version 6.3…
- CVE-2017-7286Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2017-7288Cross-site scripting (XSS) vulnerability in Zimbra Collabora…
- CVE-2017-7293The Dolby DAX2 and DAX3 API services are vulnerable to a pri…
- CVE-2017-7294The vmw_surface_define_ioctl function in drivers/gpu/drm/vmw…7.8
- CVE-2017-7295An issue was discovered in Contiki Operating System 3.0. A u…
- CVE-2017-7296An issue was discovered in Contiki Operating System 3.0. A P…
- CVE-2017-7297Rancher Labs rancher server 1.2.0+ is vulnerable to authenti…8.8
- CVE-2017-7298In Moodle 3.2.2+, there is XSS in the Course summary filter …
Are you affected by CVE-2017-7290?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
