Description
Multiple SQL injection vulnerabilities in admin.php in phpHoo3 allow remote attackers to execute arbitrary SQL commands via the (1) ADMIN_USER (USER) and (2) ADMIN_PASS (PASS) parameters during a login. NOTE: CVE disputes this vulnerability, since ADMIN_USER/ADMIN_PASS are initialized before use
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 25 Sep 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-25T16:07:11.501Z
Reserved: 2007-05-08T00:00:00.000Z
Link: CVE-2007-2534
Updated: 2024-08-07T13:42:33.409Z
Status : Modified
Published: 2007-05-09T00:19:00.000
Modified: 2026-04-23T00:35:47.467
Link: CVE-2007-2534
No data.
OpenCVE Enrichment
No data.
Weaknesses