CVE Database
/

CVE-2007-2314

Back to search

CVE-2007-2314

Published: Apr 26, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple SQL injection vulnerabilities in Crea-Book 1.0, and possibly earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) pseudo or (2) passe parameter to (a) configurer.php, (b) connect.php, (c) delete.php, (d) delete2.php, (e) index.php, (f) infos.php, (g) membres.php, (h) modif-infos.php, (i) modif-message.php, (j) modif.php, (k) uninstall.php, or (l) uninstall_table.php in admin/, different vectors than CVE-2007-2000. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

VendorProductVersions

n/a

n/a

affected
n/a

References

34819
vdb-entry
x_refsource_OSVDB
34820
vdb-entry
x_refsource_OSVDB
34825
vdb-entry
x_refsource_OSVDB
34829
vdb-entry
x_refsource_OSVDB
34827
vdb-entry
x_refsource_OSVDB
24862
third-party-advisory
x_refsource_SECUNIA
34824
vdb-entry
x_refsource_OSVDB
34826
vdb-entry
x_refsource_OSVDB
34822
vdb-entry
x_refsource_OSVDB
34823
vdb-entry
x_refsource_OSVDB
34818
vdb-entry
x_refsource_OSVDB
34821
vdb-entry
x_refsource_OSVDB
34828
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now