CVE-2007-6579
Multiple SQL injection vulnerabilities in Ip Reg 0.3 allow remote attackers to execute arbitrary SQL commands via the vlan_id parameter to (1) vlanview.php, (2) vlanedit.php, and (3) vlandel.php; the (4) assetclassgroup_id parameter to…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.71%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple SQL injection vulnerabilities in Ip Reg 0.3 allow remote attackers to execute arbitrary SQL commands via the vlan_id parameter to (1) vlanview.php, (2) vlanedit.php, and (3) vlandel.php; the (4) assetclassgroup_id parameter to assetclassgroupview.php; the (5) subnet_id parameter to nodelist.php; and unspecified other vectors. NOTE: it was later reported that the vlanview.php and vlandel.php vectors are also in 0.4.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.71% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- ip reg/ip reg
- Source
- cve@mitre.org
References
- http://osvdb.org/39776
- http://osvdb.org/39777
- http://osvdb.org/39778
- http://osvdb.org/39779
- http://osvdb.org/39780
- http://www.inj3ct-it.org/exploit/ipreg0.3.txt
- http://www.securityfocus.com/bid/26993Exploit
- https://www.exploit-db.com/exploits/4771
- http://osvdb.org/39776
- http://osvdb.org/39777
- http://osvdb.org/39778
- http://osvdb.org/39779
- http://osvdb.org/39780
- http://www.inj3ct-it.org/exploit/ipreg0.3.txt
- http://www.securityfocus.com/bid/26993Exploit
- https://www.exploit-db.com/exploits/4771
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.