3830Third-party advisory
http://securityreason.com/securityalert/3830 CVE-2008-1968
Cezanne 7 - 'cflookup.asp?FUNID' SQL Injection
Record summary
CVE-2008-1968 has a selected CVSS score of 6.0; EIP currently links 2 catalogued exploits.
Description
Multiple SQL injection vulnerabilities in Cezanne 7 allow remote authenticated users to execute arbitrary SQL commands via the FUNID parameter to (1) CFLookup.asp and (2) CznCommon/CznCustomContainer.asp.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBCezanne 7 - 'cflookup.asp?FUNID' SQL InjectionExploitDB exploitby Juan de la Fuente CostaNot analyzed1 file
ExploitDBCezanne 7 - '/CznCommon/CznCustomContainer.asp?FUNID' SQL InjectionExploitDB exploitby Juan de la Fuente CostaNot analyzed1 file
References
6s21sec.com
http://www.s21sec.com/avisos/s21sec-43-en.txt 20080414 S21SEC-043-en:Cezanne SW Blind SQL Injectionmailing list
http://www.securityfocus.com/archive/1/490843/100/0/threaded 28773vdb entry
http://www.securityfocus.com/bid/28773 cezanne-funid-sql-injection(41816)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/41816 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-1968