Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2007-4956

Multiple SQL injection vulnerabilities in KwsPHP 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the pseudo parameter to login.php, (2) the id parameter to index.php in a carnet editer action in the Member_Space (espace_membre) module, or (3) the typenav parameter to index.php in a browser aff action in the stats module.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.029
EPSS Ranking 85.6%
CVSS Severity
CVSS v2 Score 7.5
References
Products affected by CVE-2007-4956
  • Kwsphp » Kwsphp » Version: 1.0
    cpe:2.3:a:kwsphp:kwsphp:1.0


Contact Us

Shodan ® - All rights reserved