CVE-2007-0971
Multiple SQL injection vulnerabilities in Jupiter CMS 1.1.5 allow remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header and certain other HTTP headers, which set the ip variable that is used in SQL queries performed by…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.24%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple SQL injection vulnerabilities in Jupiter CMS 1.1.5 allow remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header and certain other HTTP headers, which set the ip variable that is used in SQL queries performed by index.php and certain other PHP scripts. NOTE: the attack vector might involve _SERVER.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.24% probability · 67th percentile
- CISA KEV
- Not listed
- Affected
- jupiter cms/jupiter cms
- Source
- cve@mitre.org
References
- http://mgsdl.free.fr/advisories/12070214.txtVendor Advisory
- http://osvdb.org/33727
- http://www.acid-root.new.fr/advisories/12070214.txtVendor Advisory
- http://www.securityfocus.com/archive/1/460076/100/0/threaded
- http://www.securityfocus.com/archive/1/460100/100/0/threaded
- http://www.securityfocus.com/bid/22560Exploit
- https://www.exploit-db.com/exploits/3310
- http://mgsdl.free.fr/advisories/12070214.txtVendor Advisory
- http://osvdb.org/33727
- http://www.acid-root.new.fr/advisories/12070214.txtVendor Advisory
- http://www.securityfocus.com/archive/1/460076/100/0/threaded
- http://www.securityfocus.com/archive/1/460100/100/0/threaded
- http://www.securityfocus.com/bid/22560Exploit
- https://www.exploit-db.com/exploits/3310
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.