Vulnerability CVE-2007-1909


Published: 2007-04-10   Modified: 2012-02-12

Description:
SQL injection vulnerability in login.php in Ryan Haudenschilt Battle.net Clan Script for PHP 1.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) user or (2) pass parameter.

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Ryan haudenschilt -> Battle.net clan script 

 References:
http://www.vupen.com/english/advisories/2007/1313
http://www.securityfocus.com/bid/23383
http://www.milw0rm.com/exploits/3691
http://osvdb.org/34747
http://secunia.com/advisories/24838

Copyright 2024, cxsecurity.com

 

Back to Top