Record summary

CVE-2007-5430 has a selected CVSS score of 7.5; EIP currently links 3 catalogued exploits.

Description

Multiple SQL injection vulnerabilities in Stride 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the p parameter to main.php in the Content Management System, (2) the id parameter in a sto cmd action to shop.php in the Merchant subsystem, or the (3) course or (4) provider parameter to detail.php in the Courses subsystem.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
3

Proofs of concept

3

Catalogued exploits

ExploitDBScott Manktelow Design Stride 1.0 Courses - 'detail.php' Multiple SQL InjectionsExploitDB exploitby duritoNot analyzed1 file
ExploitDB

PoC details
ExploitDBScott Manktelow Design Stride 1.0 - 'Content Management System main.php' SQL InjectionExploitDB exploitby duritoNot analyzed1 file
ExploitDB

PoC details
ExploitDBScott Manktelow Design Stride 1.0 - 'Merchant shop.php' SQL InjectionExploitDB exploitby duritoNot analyzed1 file
ExploitDB

PoC details

References

10