CVE-2007-6266 Information
Feb 14, 2021
cve
Description
Multiple SQL injection vulnerabilities in bcoos 1.0.10 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the gid parameter to modules/arcade/index.php in a show_stats action or the lid parameter to (2) modules/myalbum/ratephoto.php or (3) modules/mylinks/ratelink.php different vectors than CVE-2007-5104.
Reference
http://lostmon.blogspot.com/2007/11/bcoops-sql-injection-and-cross-site.html http://secunia.com/advisories/26945 http://www.securityfocus.com/bid/26629 https://exchange.xforce.ibmcloud.com/vulnerabilities/36752
Share on: