CVE-2007-1019
webSPELL 4.01.02 - SQL Injection
Title source: llmDescription
SQL injection vulnerability in news.php in webSPELL 4.01.02, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the showonly parameter to index.php, a different vector than CVE-2006-5388.
Exploits (1)
References (6)
Scores
EPSS
0.0277
EPSS Percentile
86.1%
Details
Status
published
Products (1)
webspell/webspell
4.01.02
Published
Feb 21, 2007
Tracked Since
Feb 18, 2026