Multiple SQL injection vulnerabilities in AuraCMS 1.5rc allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) hal.php, (2) cetak.php, (3) lihat.php, (4) pesan.php, and (5) teman.php, different vectors than CVE-2007-4171. NOTE: the scripts may be accessed through requests to the product's top-level default URI, using the pilih parameter, in some circumstances.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2007-09-11T18:00:00
Updated: 2017-09-28T12:57:01
Reserved: 2007-09-11T00:00:00
Link: CVE-2007-4804
JSON object: View
NVD Information
Status : Modified
Published: 2007-09-11T18:17:00.000
Modified: 2017-09-29T01:29:23.347
Link: CVE-2007-4804
JSON object: View
Redhat Information
No data.
CWE