27820Third-party advisory
http://secunia.com/advisories/27820 CVE-2007-6127
project alumni 1.0.9 - Cross-Site Scripting / SQL Injection
Record summary
CVE-2007-6127 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Multiple SQL injection vulnerabilities in project alumni 1.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the year parameter to (1) view.page.inc.php, which is reachable through a view action to index.php; or (2) the year parameter to news.page.inc.php, which is reachable through a news action to index.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBproject alumni 1.0.9 - Cross-Site Scripting / SQL InjectionExploitDB exploitby tomplixseeNot analyzed1 file
References
626564vdb entry
http://www.securityfocus.com/bid/26564 ADV-2007-3999vdb entry
http://www.vupen.com/english/advisories/2007/3999 projectalumni-index-sql-injection(38620)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/38620 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-6127 4655exploit
https://www.exploit-db.com/exploits/4655