CVE-2007-1231 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 1.6% (pctl 75)
Patch early
A public exploit exists.
Description
Multiple cross-site scripting (XSS) vulnerabilities in SQLiteManager 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) database name, (2) table name, (3) ViewName, (4) view, (5) trigger, and (6) function fields in main.php and certain other files.
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
| EPSS | 1.61% — more likely to be exploited than 75% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-03-03 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| sqlitemanager | sqlitemanager |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | SQLiteManager 1.2 - 'main.php' Cross-Site Scripting | 2009-08-10 |
| exploit-db | SQLiteManager 1.2 - 'main.php' Multiple HTML Injection Vulnerabilities | 2007-02-26 |
References
- http://osvdb.org/34634
- http://securityreason.com/securityalert/2366
- http://www.securityfocus.com/archive/1/461304/100/0/threaded
- http://www.securityfocus.com/bid/22731
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32692
- http://osvdb.org/34634
- http://securityreason.com/securityalert/2366
- http://www.securityfocus.com/archive/1/461304/100/0/threaded
- http://www.securityfocus.com/bid/22731
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32692
→ the Explorer · watch your stack · NVD