CVE-2007-6667 Information

Description

SQL injection vulnerability in faq.php in MyPHP Forum 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the member.php vector is already covered by CVE-2005-0413.

Reference

http://osvdb.org/39781 http://osvdb.org/39782 http://www.securityfocus.com/bid/27083 https://exchange.xforce.ibmcloud.com/vulnerabilities/39347 https://www.exploit-db.com/exploits/4822

Share on: