CVE-2007-6134

PHPKIT 1.6.4pl1 - SQL Injection

Title source: llm

Description

SQL injection vulnerability in pkinc/public/article.php in PHPKIT 1.6.4pl1 allows remote attackers to execute arbitrary SQL commands via the contentid parameter in an article action to include.php, a different vector than CVE-2006-1773.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Shadowleet · perlwebappsphp
https://www.exploit-db.com/exploits/4646

Scores

EPSS 0.0055
EPSS Percentile 68.0%

Details

CWE
CWE-89
Status published
Products (1)
phpkit/phpkit 1.6.4pl1
Published Nov 27, 2007
Tracked Since Feb 18, 2026