VulnerabilityModified
CVE-2007-4111
SQL injection vulnerability in the login script in Real Estate listing website application template, when logging in as user or manager, allows remote attackers to execute arbitrary SQL commands via the Password parameter.
MEDIUM 6.8EPSS 1.07%
Does this matter?
Lower severity and a low EPSS score (1.07%). Track it; it rarely justifies an emergency change on its own.
Description
SQL injection vulnerability in the login script in Real Estate listing website application template, when logging in as user or manager, allows remote attackers to execute arbitrary SQL commands via the Password parameter.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.07% probability · 63th percentile
- CISA KEV
- Not listed
- Affected
- codewidgets/real estate listing website application template
- Source
- cve@mitre.org
References
- http://outlaw.aria-security.info/?p=10
- http://secunia.com/advisories/26268Vendor Advisory
- http://securityreason.com/securityalert/2949
- http://www.securityfocus.com/archive/1/474934/100/0/threaded
- http://www.securityfocus.com/bid/25115
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35667
- http://outlaw.aria-security.info/?p=10
- http://secunia.com/advisories/26268Vendor Advisory
- http://securityreason.com/securityalert/2949
- http://www.securityfocus.com/archive/1/474934/100/0/threaded
- http://www.securityfocus.com/bid/25115
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35667
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.