CVE-2007-3652
CRITICALFarsi Script FaName 1.0 - SQL Injection via id Parameter
Title source: llmDescription
SQL injection vulnerability in class/page.php in Farsi Script (aka FaScript) FaName 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: this might be the same issue as CVE-2008-0328.
References (2)
Core 2
Core References
Various Sources x_refsource_misc
http://descriptions.securescout.com/tc/17972
Various Sources x_refsource_misc
http://www.netvigilance.com/advisory0042
Scores
CVSS v3
9.8
EPSS
0.0104
EPSS Percentile
60.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-89
Status
published
Products (1)
fascript/faname
1.0
Published
Jul 09, 2008
Tracked Since
Feb 18, 2026