CVE-2007-3190

Just For Fun Network Management System 0.8.3 - SQL Injection via User and Pass Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-3190. PoCs published by Tim Brown.

AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in JFFNMS versions prior to 0.8.4-pre3. The PoC manipulates the SQL query logic via the 'user' parameter in the authentication process to bypass authentication and potentially access sensitive information.

Description

Multiple SQL injection vulnerabilities in auth.php in Just For Fun Network Management System (JFFNMS) 0.8.3, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) user and (2) pass parameters.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Tim Brown · textwebappsphp
https://www.exploit-db.com/exploits/30171

This exploit demonstrates an SQL injection vulnerability in JFFNMS versions prior to 0.8.4-pre3. The PoC manipulates the SQL query logic via the 'user' parameter in the authentication process to bypass authentication and potentially access sensitive information.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Just For Fun Network Management and Monitoring System (JFFNMS) < 0.8.4-pre3
No auth needed
Prerequisites: Access to the target application's authentication endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2007/dsa-1374
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/471039/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26769
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24414
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25587
Mailing List mailing-list x_refsource_fulldisc
http://marc.info/?l=full-disclosure&m=118151087109711&w=2

Scores

EPSS 0.0145
EPSS Percentile 69.9%

Details

Status published
Products (1)
jffnms/just_for_fun_network_management_system 0.8.3
Published Jun 12, 2007
Tracked Since Feb 18, 2026