Lucene search

K
cve[email protected]CVE-2007-0695
HistoryFeb 03, 2007 - 10:28 p.m.

CVE-2007-0695

2007-02-0322:28:00
CWE-89
web.nvd.nist.gov
39
cve
2007
0695
sql injection
free lan
flip
remote attackers
arbitrary sql commands
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.5 High

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

72.2%

Multiple SQL injection vulnerabilities in Free LAN In(tra|ter)net Portal (FLIP) before 1.0-RC3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: some sources mention the escape_sqlData, implode_sql, and implode_sqlIn functions, but these are protection schemes, not the vulnerable functions.

Affected configurations

NVD
Node
free_lan_intra_internet_portalfree_lan_intra_internet_portalRange1.0_rc2
OR
free_lan_intra_internet_portalfree_lan_intra_internet_portalMatch0.9.0.730
OR
free_lan_intra_internet_portalfree_lan_intra_internet_portalMatch0.9.0.1029
OR
free_lan_intra_internet_portalfree_lan_intra_internet_portalMatch1.0_rc1

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.5 High

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

72.2%

Related for CVE-2007-0695