Vulnerability CVE-2007-6269


Published: 2007-12-07   Modified: 2012-02-12

Description:
Multiple SQL injection vulnerabilities in xlaabsolutenm.aspx in Absolute News Manager.NET 5.1 allow remote attackers to execute arbitrary SQL commands via the (1) z, (2) pz, (3) ord, and (4) sort parameters.

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Xigla -> Absolute news manager.net 

 References:
http://marc.info/?l=bugtraq&m=119678724111351&w=2
http://www.procheckup.com/Vulnerability_PR07-39.php
http://www.securityfocus.com/bid/26692
http://www.xigla.com/news/default.aspx
http://www.xigla.com/security/ANMNET51-SecurityUpdate20071128.zip
https://exchange.xforce.ibmcloud.com/vulnerabilities/38871

Copyright 2022, cxsecurity.com

 

Back to Top