CVE-2007-6373
GestDown 1.00 Beta - SQL Injection via categorie or id Parameter
Title source: llmDescription
Multiple SQL injection vulnerabilities in GestDown 1.00 Beta allow remote attackers to execute arbitrary SQL commands via the (1) categorie parameter to catdownload.php, or the id parameter to (2) download.php or (3) hitcounter.php.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/38945
Exploit mailing-list
x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=119730791316604&w=2
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/26799
Scores
EPSS
0.0112
EPSS Percentile
63.1%
Details
CWE
CWE-89
Status
published
Products (1)
gestdown/gestdown
1.00_beta
Published
Dec 15, 2007
Tracked Since
Feb 18, 2026