Vulnerability Description
Multiple SQL injection vulnerabilities in admin.php in phpHoo3 allow remote attackers to execute arbitrary SQL commands via the (1) ADMIN_USER (USER) and (2) ADMIN_PASS (PASS) parameters during a login. NOTE: CVE disputes this vulnerability, since ADMIN_USER/ADMIN_PASS are initialized before use
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phphoo3 | Phphoo3 | All versions |
Related Weaknesses (CWE)
References
- http://osvdb.org/36180
- http://securityreason.com/securityalert/2669
- http://www.attrition.org/pipermail/vim/2007-May/001597.htmlExploit
- http://www.securityfocus.com/archive/1/467839/100/0/threaded
- http://www.securityfocus.com/bid/23854Exploit
- http://osvdb.org/36180
- http://securityreason.com/securityalert/2669
- http://www.attrition.org/pipermail/vim/2007-May/001597.htmlExploit
- http://www.securityfocus.com/archive/1/467839/100/0/threaded
- http://www.securityfocus.com/bid/23854Exploit
FAQ
What is CVE-2007-2534?
CVE-2007-2534 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Multiple SQL injection vulnerabilities in admin.php in phpHoo3 allow remote attackers to execute arbitrary SQL commands via the (1) ADMIN_USER (USER) and (2) ADMIN_PASS (PASS) parameters during a logi...
How severe is CVE-2007-2534?
CVE-2007-2534 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2007-2534?
Check the references section above for vendor advisories and patch information. Affected products include: Phphoo3 Phphoo3.