Lucene search

K
cve[email protected]CVE-2007-4068
HistoryJul 30, 2007 - 5:30 p.m.

CVE-2007-4068

2007-07-3017:30:00
web.nvd.nist.gov
20
sql injection
webyapar 2.0
vulnerability
remote attack
arbitrary commands
nvd

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

8.5 High

AI Score

Confidence

Low

0.006 Low

EPSS

Percentile

78.5%

Multiple SQL injection vulnerabilities in Webyapar 2.0 allow remote attackers to execute arbitrary SQL commands via (1) the kat_id parameter to the default URI in a download action or (2) the id parameter to the default URI in a duyurular_detay action.

Affected configurations

NVD
Node
webyaparwebyaparMatch2.0
CPENameOperatorVersion
webyapar:webyaparwebyapareq2.0

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

8.5 High

AI Score

Confidence

Low

0.006 Low

EPSS

Percentile

78.5%

Related for CVE-2007-4068