Vulnerability Name: | CVE-2007-4456 (CCN-36113) | ||||||||
Assigned: | 2007-08-20 | ||||||||
Published: | 2007-08-20 | ||||||||
Updated: | 2018-10-15 | ||||||||
Summary: | SQL injection vulnerability in index.php in the SimpleFAQ (com_simplefaq) 2.11 component for Mambo allows remote attackers to execute arbitrary SQL commands via the aid parameter. Note: it was later reported that 2.40 is also affected, and that the component can be used in Joomla! in addition to Mambo. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 7.1 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:H/RL:U/RC:UR)
7.1 High (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:H/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-89 | ||||||||
Vulnerability Consequences: | Data Manipulation | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Mon Aug 20 2007 - 15:31:17 CDT Mambo Component SimpleFAQ V2.11 - Remote SQL Injection Source: CCN Type: BugTraq Mailing List, Mon Aug 20 2007 - 16:02:26 CDT Joomla Component SimpleFAQ V2.11 - Remote SQL Injection Source: MITRE Type: CNA CVE-2007-4456 Source: CCN Type: SA26556 Joomla SimpleFAQ Component "aid" SQL Injection Source: SECUNIA Type: UNKNOWN 26556 Source: SREASON Type: UNKNOWN 3041 Source: CCN Type: OSVDB ID: 37174 SimpleFAQ Component for Joomla! index.php aid Parameter SQL Injection Source: CCN Type: Parkview Consultants Web site SimpleFAQ Source: BUGTRAQ Type: UNKNOWN 20070820 Mambo Component SimpleFAQ V2.11 - Remote SQL Injection Source: BUGTRAQ Type: UNKNOWN 20070820 Joomla Component SimpleFAQ V2.11 - Remote SQL Injection Source: BID Type: Exploit 25376 Source: CCN Type: BID-25376 SimpleFAQ Index.PHP SQL Injection Vulnerability Source: XF Type: UNKNOWN simplefaq-index-sql-injection(36113) Source: XF Type: UNKNOWN simplefaq-index-sql-injection(36113) Source: EXPLOIT-DB Type: UNKNOWN 4296 | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |