CVE-2007-5458

Alorys-hebergement Kwsphp - SQL Injection

Title source: rule

Description

SQL injection vulnerability in index.php in the newsletter module 1.0 for KwsPHP, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the newsletter parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by s4mi · perlwebappsphp
https://www.exploit-db.com/exploits/4523

Scores

EPSS 0.0046
EPSS Percentile 64.3%

Details

CWE
CWE-89
Status published
Products (2)
alorys-hebergement/kwsphp
alorys-hebergement/newsletter_module 1.00
Published Oct 14, 2007
Tracked Since Feb 18, 2026