CVE-2007-6566 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.4% (pctl 83)
Patch early
A public exploit exists.
Description
SQL injection vulnerability in post.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to execute arbitrary SQL commands via the subcatid parameter to index.php.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.38% — more likely to be exploited than 83% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-12-28 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| xzero scripts | xzero community classifieds |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | XZero Community Classifieds 4.95.11 - Local File Inclusion / SQL Injection | 2007-12-26 |
References
- http://en.rstzone.org/xzero-community-classifieds-v4-95-11-lfi-sql-in-t9394.rst
- http://osvdb.org/39740
- http://secunia.com/advisories/28250
- http://www.securityfocus.com/archive/1/485545/100/0/threaded
- http://www.securityfocus.com/bid/27042
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39259
- https://www.exploit-db.com/exploits/4794
- http://en.rstzone.org/xzero-community-classifieds-v4-95-11-lfi-sql-in-t9394.rst
- http://osvdb.org/39740
- http://secunia.com/advisories/28250
- http://www.securityfocus.com/archive/1/485545/100/0/threaded
- http://www.securityfocus.com/bid/27042
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39259
- https://www.exploit-db.com/exploits/4794
→ the Explorer · watch your stack · NVD