Multiple SQL injection vulnerabilities in AuraCMS 1.5rc allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) hal.php, (2) cetak.php, (3) lihat.php, (4) pesan.php, and (5) teman.php, different vectors than CVE-2007-4171. NOTE: the scripts may be accessed through requests to the product's top-level default URI, using the pilih parameter, in some circumstances.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2007-09-11T18:00:00

Updated: 2017-09-28T12:57:01

Reserved: 2007-09-11T00:00:00


Link: CVE-2007-4804

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2007-09-11T18:17:00.000

Modified: 2017-09-29T01:29:23.347


Link: CVE-2007-4804

JSON object: View

cve-icon Redhat Information

No data.

CWE