Lucene search

K
cveMitreCVE-2007-3539
HistoryJul 03, 2007 - 8:30 p.m.

CVE-2007-3539

2007-07-0320:30:00
CWE-89
mitre
web.nvd.nist.gov
31
cve-2007-3539
sql injection
quickticket
quicktalk forum
remote attack
security vulnerability
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.5

Confidence

Low

EPSS

0.009

Percentile

83.1%

Multiple SQL injection vulnerabilities in QuickTicket 1.2 build:20070621 and QuickTalk Forum 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) t and (2) f parameters in (a) qti_ind_post.php and (b) qti_ind_post_prt.php; (3) dir and (4) order parameters in qti_ind_member.php; (5) id parameter in qti_usr.php; and the (6) f parameter in qti_ind_topic.php. NOTE: it was later reported that vector 5 also affects 1.4, 1.5, and 1.5.0.3.

Affected configurations

Nvd
Node
qt-cutequicktalk_forumMatch1.3
OR
qt-cutequicktalk_forumMatch1.4
OR
qt-cutequicktalk_forumMatch1.5.0.3
OR
qt-cutequickticketMatch1.2_build_2007_06_21
VendorProductVersionCPE
qt-cutequicktalk_forum1.3cpe:2.3:a:qt-cute:quicktalk_forum:1.3:*:*:*:*:*:*:*
qt-cutequicktalk_forum1.4cpe:2.3:a:qt-cute:quicktalk_forum:1.4:*:*:*:*:*:*:*
qt-cutequicktalk_forum1.5.0.3cpe:2.3:a:qt-cute:quicktalk_forum:1.5.0.3:*:*:*:*:*:*:*
qt-cutequickticket1.2_build_2007_06_21cpe:2.3:a:qt-cute:quickticket:1.2_build_2007_06_21:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.5

Confidence

Low

EPSS

0.009

Percentile

83.1%

Related for CVE-2007-3539