CVE-2017-7290
HIGHXOOPS < 2.5.8.1 - Authenticated SQL Injection via findusers.php url Parameter
Title source: llmDescription
SQL injection vulnerability in XOOPS 2.5.7.2 and other versions before 2.5.8.1 allows remote authenticated administrators to execute arbitrary SQL commands via the url parameter to findusers.php. An example attack uses "into outfile" to create a backdoor program.
References (2)
Core 2
Core References
Exploit, Patch, Third Party Advisory x_refsource_misc
https://gist.github.com/jk1986/3b304ac6b4ae52ae667bba380c2dce19
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/97230
Scores
CVSS v3
7.2
EPSS
0.0230
EPSS Percentile
81.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (3)
xoops/xoops
2.5.7.2
xoops/xoops
2.5.7.3
xoops/xoops
2.5.8.1
Published
Mar 30, 2017
Tracked Since
Feb 18, 2026