CVE-2007-1634

Variable extraction vulnerability in grab_globals.php in Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote attackers to conduct SQL injection attacks via the _FILES[DB][tmp_name] parameter to print.php, which overwrites the $DB variable with dynamic variable evaluation.
Configurations

Configuration 1 (hide)

cpe:2.3:a:net_portal_dynamic_system:net_portal_dynamic_system:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2007-03-23 22:19

Updated : 2024-02-04 17:13


NVD link : CVE-2007-1634

Mitre link : CVE-2007-1634

CVE.ORG link : CVE-2007-1634


JSON object : View

Products Affected

net_portal_dynamic_system

  • net_portal_dynamic_system