CVE-2007-0350

SmE FileMailer < 1.21 - SQL Injection via ps, us, f, or code Parameter

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in (a) index.php and (b) dl.php in SmE FileMailer 1.21 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ps, (2) us, (3) f, or (4) code parameter. NOTE: the us vector in index.php is already covered by CVE-2007-0346.

References (5)

Core 5
Core References
Various Sources mailing-list x_refsource_vim
http://attrition.org/pipermail/vim/2007-January/001244.html
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2007-01/0395.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/31533
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/32833
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/0221

Scores

EPSS 0.0110
EPSS Percentile 62.3%

Details

CWE
CWE-89
Status published
Products (1)
sme/filemailer < 1.21
Published Jan 19, 2007
Tracked Since Feb 18, 2026