CVE Database
/

CVE-2007-6366

Back to search

CVE-2007-6366

Published: Dec 15, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple SQL injection vulnerabilities in SineCMS 2.3.4 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to mods/Calendar/index.php, accessed through a Calendar info action to mods.php; the id parameter to admin/mods_adm.php in a (2) Guestbook modifica or (3) Calendar modify action; or the (4) mese or (5) anno parameter to admin/mods_adm.php in a Calendar action. NOTE: the component for vectors 2 through 5 might be limited to administrators.

VendorProductVersions

n/a

n/a

affected
n/a

References

3444
third-party-advisory
x_refsource_SREASON
27949
third-party-advisory
x_refsource_SECUNIA
4693
exploit
x_refsource_EXPLOIT-DB
sinecms-mods-sql-injection(38895)
vdb-entry
x_refsource_XF

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now