34470vdb entry
http://osvdb.org/34470 CVE-2007-1811
XOOPS Module Tiny Event 1.01 - 'id' SQL Injection
Record summary
CVE-2007-1811 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
SQL injection vulnerability in index.php in the Tiny Event (tinyevent) 1.01 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBXOOPS Module Tiny Event 1.01 - 'id' SQL InjectionExploitDB exploitby ajannNot analyzed1 file
References
4xoops-tinyevent-index-sql-injection(33359)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/33359 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-1811 3625exploit
https://www.exploit-db.com/exploits/3625