VulnerabilityModified
CVE-2007-4922
SQL injection vulnerability in play.php in the jeuxflash 1.0 module for KwsPHP allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a play ac action to index.php.
MEDIUM 6.5EPSS 0.86%
Does this matter?
Lower severity and a low EPSS score (0.86%). Track it; it rarely justifies an emergency change on its own.
Description
SQL injection vulnerability in play.php in the jeuxflash 1.0 module for KwsPHP allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a play ac action to index.php. NOTE: some details are obtained from third party information.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 0.86% probability · 56th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- jeuxflash/jeuxflash module · kwsphp/kwsphp
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/25658Exploit
- http://www.vupen.com/english/advisories/2007/3172Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36601
- https://www.exploit-db.com/exploits/4400
- http://www.securityfocus.com/bid/25658Exploit
- http://www.vupen.com/english/advisories/2007/3172Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36601
- https://www.exploit-db.com/exploits/4400
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.