peter bassill · operator
$ cve CVE-2007-4522 JSON

CVE-2007-4522 EXPLOIT

6.0
MEDIUM · CVSS 2.0 · EPSS 1.7% (pctl 77)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote authenticated users to execute arbitrary SQL commands via one or more of the following vectors: the (1) id parameter to (a) pages/delete_page.php, (b) navigation/delete_menu.php, and (c) navigation/delete_item.php in admin/; the (2) menu_id, (3) name, (3) page_id, and (4) url parameters in (d) admin/navigation/do_new_item.php; the (5) new_menuname parameter in (e) admin/navigation/do_new_nav.php; and (6) area1, name, and url parameters to (f) admin/pages/do_new_page.php. NOTE: some vectors might be reachable through the url and name parameters to (g) admin/navigation/new_nav_item.php. NOTE: the original disclosure does not precisely state which vectors are associated with SQL injection versus XSS.

Scoring

CVSS6.0 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:S/C:P/I:P/A:P
EPSS1.73% — more likely to be exploited than 77% of all CVEs
On CISA KEVno
Public exploityes
Published2007-08-25
Last modified2026-06-16

Affected (1)

VendorProduct
ripe website managerripe website manager

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD