CVE-2007-2599

TutorialCMS <1.00 - SQL Injection

Title source: llm

Description

Multiple SQL injection vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) catFile parameter to (a) browseCat.php or (b) browseSubCat.php; the (2) id parameter to (c) openTutorial.php, (d) topFrame.php, or (e) admin/editListing.php; or (3) the search parameter to search.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Silentz · perlwebappsphp
https://www.exploit-db.com/exploits/3887

Scores

EPSS 0.0244
EPSS Percentile 85.2%

Details

Status published
Products (1)
wavelink_media/tutorialcms < 1.00
Published May 11, 2007
Tracked Since Feb 18, 2026