CVE-2007-3909

Multiple SQL injection vulnerabilities in Bandersnatch 0.4 allow remote attackers to execute arbitrary SQL commands via the (1) date and (2) limit parameters to index.php, and other unspecified vectors.
Configurations

Configuration 1 (hide)

cpe:2.3:a:bandersnatch:bandersnatch:0.4:*:*:*:*:*:*:*

History

21 Nov 2024, 00:34

Type Values Removed Values Added
References () http://secunia.com/advisories/26202 - Vendor Advisory () http://secunia.com/advisories/26202 - Vendor Advisory
References () http://www.osvdb.org/38268 - () http://www.osvdb.org/38268 -
References () http://www.portcullis-security.com/uplds/advisories/Bandersnatch%20-%2007-006.txt - () http://www.portcullis-security.com/uplds/advisories/Bandersnatch%20-%2007-006.txt -
References () http://www.securityfocus.com/bid/25094 - () http://www.securityfocus.com/bid/25094 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/35406 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/35406 -

Information

Published : 2007-07-19 17:30

Updated : 2024-11-21 00:34


NVD link : CVE-2007-3909

Mitre link : CVE-2007-3909

CVE.ORG link : CVE-2007-3909


JSON object : View

Products Affected

bandersnatch

  • bandersnatch
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')