CVE-2007-0502

Webspell - SQL Injection

Title source: rule

Description

SQL injection vulnerability in gallery.php in webSPELL 4.01.02 allows remote attackers to execute arbitrary SQL commands via the picID parameter, a different vector than CVE-2007-0492.

Exploits (1)

exploitdb WORKING POC VERIFIED
by r00t · phpwebappsphp
https://www.exploit-db.com/exploits/3172

Scores

EPSS 0.0137
EPSS Percentile 80.0%

Classification

Status draft

Affected Products (1)

webspell/webspell

Timeline

Published Jan 25, 2007
Tracked Since Feb 18, 2026