CVE Database
/

CVE-2007-5643

Back to search

CVE-2007-5643

Published: Oct 23, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple SQL injection vulnerabilities in Lussumo Vanilla 1.1.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the CategoryID parameter to ajax/sortcategories.php or (2) an unspecified vector to ajax/sortroles.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

26145
vdb-entry
x_refsource_BID
ADV-2007-3571
vdb-entry
x_refsource_VUPEN
27348
third-party-advisory
x_refsource_SECUNIA
4548
exploit
x_refsource_EXPLOIT-DB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now