CVE-2007-6373

GestDown 1.00 Beta - SQL Injection via categorie or id Parameter

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in GestDown 1.00 Beta allow remote attackers to execute arbitrary SQL commands via the (1) categorie parameter to catdownload.php, or the id parameter to (2) download.php or (3) hitcounter.php.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/38945
Exploit mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=119730791316604&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/26799

Scores

EPSS 0.0112
EPSS Percentile 63.1%

Details

CWE
CWE-89
Status published
Products (1)
gestdown/gestdown 1.00_beta
Published Dec 15, 2007
Tracked Since Feb 18, 2026