43491vdb entry
http://osvdb.org/43491 CVE-2007-5430
Scott Manktelow Design Stride 1.0 Courses - 'detail.php' Multiple SQL Injections
Record summary
CVE-2007-5430 has a selected CVSS score of 7.5; EIP currently links 3 catalogued exploits.
Description
Multiple SQL injection vulnerabilities in Stride 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the p parameter to main.php in the Content Management System, (2) the id parameter in a sto cmd action to shop.php in the Merchant subsystem, or the (3) course or (4) provider parameter to detail.php in the Courses subsystem.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 3
Proofs of concept
3Catalogued exploits
ExploitDBScott Manktelow Design Stride 1.0 Courses - 'detail.php' Multiple SQL InjectionsExploitDB exploitby duritoNot analyzed1 file
ExploitDBScott Manktelow Design Stride 1.0 - 'Content Management System main.php' SQL InjectionExploitDB exploitby duritoNot analyzed1 file
ExploitDBScott Manktelow Design Stride 1.0 - 'Merchant shop.php' SQL InjectionExploitDB exploitby duritoNot analyzed1 file
References
1043492vdb entry
http://osvdb.org/43492 43494vdb entry
http://osvdb.org/43494 3216Third-party advisory
http://securityreason.com/securityalert/3216 securityvulns.ru
http://securityvulns.ru/Sdocument4.html 20071010 Vulnerabilities digestmailing list
http://www.securityfocus.com/archive/1/482006/100/0/threaded 26036vdb entry
http://www.securityfocus.com/bid/26036 26041vdb entry
http://www.securityfocus.com/bid/26041 26046vdb entry
http://www.securityfocus.com/bid/26046 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-5430