CVE Database
/

CVE-2007-3539

Back to search

CVE-2007-3539

Published: Jul 3, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple SQL injection vulnerabilities in QuickTicket 1.2 build:20070621 and QuickTalk Forum 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) t and (2) f parameters in (a) qti_ind_post.php and (b) qti_ind_post_prt.php; (3) dir and (4) order parameters in qti_ind_member.php; (5) id parameter in qti_usr.php; and the (6) f parameter in qti_ind_topic.php. NOTE: it was later reported that vector 5 also affects 1.4, 1.5, and 1.5.0.3.

VendorProductVersions

n/a

n/a

affected
n/a

References

29299
third-party-advisory
x_refsource_SECUNIA
38957
vdb-entry
x_refsource_OSVDB
42684
vdb-entry
x_refsource_OSVDB
5222
exploit
x_refsource_EXPLOIT-DB
37606
vdb-entry
x_refsource_OSVDB
ADV-2007-2367
vdb-entry
x_refsource_VUPEN
28176
vdb-entry
x_refsource_BID
38958
vdb-entry
x_refsource_OSVDB
38959
vdb-entry
x_refsource_OSVDB
38956
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now