38475vdb entry
http://osvdb.org/38475 CVE-2007-3301
FuseTalk 2.0/3.0 - 'AuthError.cfm' SQL Injection
Record summary
CVE-2007-3301 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
SQL injection vulnerability in forum/include/error/autherror.cfm in FuseTalk allows remote attackers to execute arbitrary SQL commands via the errorcode parameter. NOTE: a patch may have been released privately between April and June 2007. NOTE: this issue may overlap CVE-2007-3273.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBFuseTalk 2.0/3.0 - 'AuthError.cfm' SQL InjectionExploitDB exploitby Ivan AlmuinaNot analyzed1 file
References
625707Third-party advisory
http://secunia.com/advisories/25707 20070619 fusetalk SQL (autherror.cfm)mailing list
http://www.securityfocus.com/archive/1/471726/100/0/threaded 24528vdb entry
http://www.securityfocus.com/bid/24528 fusetalk-autherror-sql-injection(34939)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/34939 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-3301