CVE-2007-1838

Xoops Friendfinder Module < 3.3 - SQL Injection

Title source: rule

Description

SQL injection vulnerability in view.php in the Friendfinder 3.3 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by ajann · perlwebappsphp
https://www.exploit-db.com/exploits/3597

Scores

EPSS 0.0064
EPSS Percentile 70.2%

Classification

Status draft

Affected Products (1)

xoops/friendfinder_module < 3.3

Timeline

Published Apr 03, 2007
Tracked Since Feb 18, 2026