CVE-2017-7290

HIGH

XOOPS < 2.5.8.1 - Authenticated SQL Injection via findusers.php url Parameter

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in XOOPS 2.5.7.2 and other versions before 2.5.8.1 allows remote authenticated administrators to execute arbitrary SQL commands via the url parameter to findusers.php. An example attack uses "into outfile" to create a backdoor program.

References (2)

Core 2
Core References
Exploit, Patch, Third Party Advisory x_refsource_misc
https://gist.github.com/jk1986/3b304ac6b4ae52ae667bba380c2dce19
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/97230

Scores

CVSS v3 7.2
EPSS 0.0230
EPSS Percentile 81.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (3)
xoops/xoops 2.5.7.2
xoops/xoops 2.5.7.3
xoops/xoops 2.5.8.1
Published Mar 30, 2017
Tracked Since Feb 18, 2026