Multiple SQL injection vulnerabilities in Enthusiast 3.1 allow remote attackers to execute arbitrary SQL commands via the cat parameter to (1) show_owned.php, (2) show_joined.php, and possibly other files. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
References
Configurations
History
21 Nov 2024, 00:25
Type | Values Removed | Values Added |
---|---|---|
References | () http://osvdb.org/31609 - | |
References | () http://osvdb.org/31610 - | |
References | () http://secunia.com/advisories/23865 - Vendor Advisory | |
References | () http://www.securityfocus.com/bid/22180 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/31666 - |
Information
Published : 2007-01-25 00:28
Updated : 2024-11-21 00:25
NVD link : CVE-2007-0484
Mitre link : CVE-2007-0484
CVE.ORG link : CVE-2007-0484
JSON object : View
Products Affected
enthusiast
- enthusiast
CWE