CVE-2007-1163

webSPELL <4.01.02 - SQL Injection

Title source: llm

Description

SQL injection vulnerability in printview.php in webSPELL 4.01.02 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter, a different vector than CVE-2007-1019, CVE-2006-5388, and CVE-2006-4783.

Exploits (1)

exploitdb WORKING POC VERIFIED
by DNX · perlwebappsphp
https://www.exploit-db.com/exploits/3351

Scores

EPSS 0.0147
EPSS Percentile 81.0%

Details

CWE
CWE-89
Status published
Products (4)
webspell/webspell 4.0
webspell/webspell 4.01.00
webspell/webspell 4.01.01
webspell/webspell < 4.01.02
Published Mar 02, 2007
Tracked Since Feb 18, 2026