CVE-2007-1122
Multiple SQL injection vulnerabilities in Mathis Dirksen-Thedens ZephyrSoft Toolbox Address Book Continued (ABC) 1.00 and 1.01 allow remote attackers to execute arbitrary SQL commands via the id parameter to the (1) updateRow and (2) deleteRow functions…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 14.9%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Multiple SQL injection vulnerabilities in Mathis Dirksen-Thedens ZephyrSoft Toolbox Address Book Continued (ABC) 1.00 and 1.01 allow remote attackers to execute arbitrary SQL commands via the id parameter to the (1) updateRow and (2) deleteRow functions in functions.php, a variant of a SQL injection issue that was fixed in 1.01. NOTE: some of these details are obtained from third party information.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
- EPSS
- 14.89% probability · 96th percentile
- CISA KEV
- Not listed
- Affected
- zephyrsoft toolbox/address book continued
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/24269Vendor Advisory
- http://sourceforge.net/project/downloading.php?group_id=153333&use_mirror=osdn&filename=abc-1.02.zip
- http://www.securityfocus.com/bid/22685Vendor Advisory
- http://www.vupen.com/english/advisories/2007/0715
- http://secunia.com/advisories/24269Vendor Advisory
- http://sourceforge.net/project/downloading.php?group_id=153333&use_mirror=osdn&filename=abc-1.02.zip
- http://www.securityfocus.com/bid/22685Vendor Advisory
- http://www.vupen.com/english/advisories/2007/0715
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.