Record summary

CVE-2007-6127 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.

Description

Multiple SQL injection vulnerabilities in project alumni 1.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the year parameter to (1) view.page.inc.php, which is reachable through a view action to index.php; or (2) the year parameter to news.page.inc.php, which is reachable through a news action to index.php.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBproject alumni 1.0.9 - Cross-Site Scripting / SQL InjectionExploitDB exploitby tomplixseeNot analyzed1 file

linked to 2 vulnerabilities

ExploitDB

PoC details

References

6