CVE-2007-3814

mkportal 1.1.1 - SQL Injection via Multiple Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-3814. PoCs published by Coloss.

AI-analyzed exploit summary This is a SQL injection exploit for MkPortal <= 1.1.1 targeting the 'reviews' and 'gallery' modules. It supports multiple forum types (phpbb, smf, mybb) and uses both direct and blind SQL injection techniques to extract data.

Description

Multiple SQL injection vulnerabilities in MKPortal 1.1.1 allow remote attackers to execute arbitrary SQL commands via (1) the idurlo field in the delete_urlo function in (a) index.php in the urlobox module; the iden field in the (2) update_file and (3) del_file functions in (b) index.php in the reviews module; the (4) idnews field in the delete_news function and the (5) idcomm field in the del_comment function in (c) index.php in the news module; the (6) idcomm field in the delete_comments function in (d) index.php in the gallery module; the iden field in the (7) edit_file, (8) update_file, and (9) del_file functions in index.php in the gallery module; the (10) ide and (11) cat fields in the slide_update function in index.php in the gallery module; the iden field in the (12) update_file and (13) del_file functions in (d) index.php in the downloads module; and other unspecified vectors.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Coloss · phpwebappsphp
https://www.exploit-db.com/exploits/4179

This is a SQL injection exploit for MkPortal <= 1.1.1 targeting the 'reviews' and 'gallery' modules. It supports multiple forum types (phpbb, smf, mybb) and uses both direct and blind SQL injection techniques to extract data.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: MkPortal <= 1.1.1
Auth required
Prerequisites: Target URL · Forum type (phpbb, smf, mybb) · Valid credentials for authenticated exploitation
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (11)

Core 11
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/41722
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/41721
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/41723
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24886
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/473495/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24891
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/4179
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/2894
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/35391
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/41719
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/41720

Scores

EPSS 0.0213
EPSS Percentile 79.5%

Details

Status published
Products (1)
mkportal/mkportal 1.1.1
Published Jul 17, 2007
Tracked Since Feb 18, 2026