CVE-2007-0350
Published Jan 19, 2007
Last updated 7 years ago
Overview
- Description
- Multiple SQL injection vulnerabilities in (a) index.php and (b) dl.php in SmE FileMailer 1.21 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ps, (2) us, (3) f, or (4) code parameter. NOTE: the us vector in index.php is already covered by CVE-2007-0346.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-89
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:sme:filemailer:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9CC39C84-0DC7-49AE-962F-4814E678B29F", "versionEndIncluding": "1.21" } ], "operator": "OR" } ] } ]