peter bassill · operator
$ cve CVE-2007-4804 JSON

CVE-2007-4804 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 3.3% (pctl 88)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in AuraCMS 1.5rc allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) hal.php, (2) cetak.php, (3) lihat.php, (4) pesan.php, and (5) teman.php, different vectors than CVE-2007-4171. NOTE: the scripts may be accessed through requests to the product's top-level default URI, using the pilih parameter, in some circumstances.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS3.35% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2007-09-11
Last modified2026-06-16

Affected (1)

VendorProduct
auracmsauracms

Public exploits

SourceTitleDate
exploit-dbAuraCMS 1.5rc - Multiple SQL Injections2007-09-09

References

→ the Explorer  ·  watch your stack  ·  NVD