CVE-2007-4210 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.9% (pctl 87)
Patch early
A public exploit exists.
Description
Multiple SQL injection vulnerabilities in module.php in LANAI (la-nai) CMS 1.2.14 allow remote attackers to execute arbitrary SQL commands via (1) the mid parameter in an faqviewgroup action in the FAQ Modules, (2) the cid parameter in the EZSHOPINGCART Modules, or (3) the gid parameter in a view action in the GALLERY Modules.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.94% — more likely to be exploited than 87% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-08-08 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| redline software | lanai cms |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Lanius CMS 1.2.14 - Multiple SQL Injections | 2007-08-06 |
| exploit-db | Lanius CMS 1.2.14 FAQ Module - 'mid' SQL Injection | 2007-08-03 |
| exploit-db | Lanius CMS 1.2.14 EZSHOPINGCART Module - 'cid' SQL Injection | 2007-08-03 |
| exploit-db | Lanius CMS 1.2.14 GALLERY Module - 'gid' SQL Injection | 2007-08-03 |
References
- http://osvdb.org/36438
- http://osvdb.org/37470
- http://osvdb.org/37471
- http://secunia.com/advisories/26339
- http://securityreason.com/securityalert/2975
- http://www.securityfocus.com/archive/1/475447
- http://www.securityfocus.com/bid/25193
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35786
- http://osvdb.org/36438
- http://osvdb.org/37470
- http://osvdb.org/37471
- http://secunia.com/advisories/26339
- http://securityreason.com/securityalert/2975
- http://www.securityfocus.com/archive/1/475447
- http://www.securityfocus.com/bid/25193
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35786
→ the Explorer · watch your stack · NVD