CVE-2007-5402 Information

Description

Multiple SQL injection vulnerabilities in Layton HelpBox 3.7.1 allow (1) remote attackers to execute arbitrary SQL commands via the sys_request_id parameter to editrequestenduser.asp; and allow remote authenticated users to execute arbitrary SQL commands via (2) the oldpassword parameter to writepwdenduser.asp and the sys_request_id parameter to (3) changerequeststatus.asp (4) editrequestuser.asp (5) requestcommentsuser.asp and (6) useractions.asp different vectors than CVE-2004-2551.

Reference

http://secunia.com/advisories/27699 http://secunia.com/secunia_research/2007-94/advisory/ http://www.securityfocus.com/bid/27187 https://exchange.xforce.ibmcloud.com/vulnerabilities/39538 https://exchange.xforce.ibmcloud.com/vulnerabilities/39539

Share on: