CVE-2007-6269 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.9% (pctl 86)
Patch early
A public exploit exists.
Description
Multiple SQL injection vulnerabilities in xlaabsolutenm.aspx in Absolute News Manager.NET 5.1 allow remote attackers to execute arbitrary SQL commands via the (1) z, (2) pz, (3) ord, and (4) sort parameters.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.88% — more likely to be exploited than 86% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-12-07 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| xigla | absolute news manager.net |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Absolute News Manager .NET 5.1 - 'xlaabsolutenm.aspx' Multiple SQL Injections | 2007-12-04 |
References
- http://marc.info/?l=bugtraq&m=119678724111351&w=2
- http://osvdb.org/40576
- http://secunia.com/advisories/27923
- http://www.procheckup.com/Vulnerability_PR07-39.php
- http://www.securityfocus.com/bid/26692
- http://www.xigla.com/news/default.aspx
- http://www.xigla.com/security/ANMNET51-SecurityUpdate20071128.zip
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38871
- http://marc.info/?l=bugtraq&m=119678724111351&w=2
- http://osvdb.org/40576
- http://secunia.com/advisories/27923
- http://www.procheckup.com/Vulnerability_PR07-39.php
- http://www.securityfocus.com/bid/26692
- http://www.xigla.com/news/default.aspx
- http://www.xigla.com/security/ANMNET51-SecurityUpdate20071128.zip
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38871
→ the Explorer · watch your stack · NVD