CVE-2007-2738

Glossaire <1.7 - SQL Injection

Title source: llm

Description

SQL injection vulnerability in glossaire-p-f.php in the Glossaire 1.7 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the sid parameter in an ImprDef action.

Exploits (1)

exploitdb WORKING POC VERIFIED
by ajann · perlwebappsphp
https://www.exploit-db.com/exploits/3932

Scores

EPSS 0.0071
EPSS Percentile 72.4%

Details

Status published
Products (1)
xoops/xoops_glossaire_module < 1.7
Published May 17, 2007
Tracked Since Feb 18, 2026