VulnerabilityModified
CVE-2007-2018
SQL injection vulnerability in msg.php in AlstraSoft Video Share Enterprise allows remote authenticated users to execute arbitrary SQL commands via the id parameter.
MEDIUM 6.5EPSS 0.93%
Does this matter?
Lower severity and a low EPSS score (0.93%). Track it; it rarely justifies an emergency change on its own.
Description
SQL injection vulnerability in msg.php in AlstraSoft Video Share Enterprise allows remote authenticated users to execute arbitrary SQL commands via the id parameter.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 0.93% probability · 59th percentile
- CISA KEV
- Not listed
- Affected
- alstrasoft/video share enterprise
- Source
- cve@mitre.org
References
- http://pridels0.blogspot.com/2007/03/alstrasoft-video-share-enterprise.html
- http://secunia.com/advisories/24836Vendor Advisory
- http://www.securityfocus.com/bid/23409
- http://www.vupen.com/english/advisories/2007/1331
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33546
- http://pridels0.blogspot.com/2007/03/alstrasoft-video-share-enterprise.html
- http://secunia.com/advisories/24836Vendor Advisory
- http://www.securityfocus.com/bid/23409
- http://www.vupen.com/english/advisories/2007/1331
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33546
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.