peter bassill · operator
$ cve CVE-2007-6172 JSON

CVE-2007-6172 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 1.6% (pctl 75)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in wpQuiz 2.7 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) viewimage.php and (2) comments.php.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS1.59% — more likely to be exploited than 75% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2007-11-30
Last modified2026-06-16

Affected (1)

VendorProduct
wire plastic designwpquiz

Public exploits

SourceTitleDate
exploit-dbwpQuiz 2.7 - Multiple SQL Injections2007-11-27

References

→ the Explorer  ·  watch your stack  ·  NVD