Multiple SQL injection vulnerabilities in MKPortal 1.1.1 allow remote attackers...
Vulnerability Description
Multiple SQL injection vulnerabilities in MKPortal 1.1.1 allow remote attackers to execute arbitrary SQL commands via (1) the idurlo field in the delete_urlo function in (a) index.php in the urlobox module; the iden field in the (2) update_file and (3) del_file functions in (b) index.php in the reviews module; the (4) idnews field in the delete_news function and the (5) idcomm field in the del_comment function in (c) index.php in the news module; the (6) idcomm field in the delete_comments function in (d) index.php in the gallery module; the iden field in the (7) edit_file, (8) update_file, and (9) del_file functions in index.php in the gallery module; the (10) ide and (11) cat fields in the slide_update function in index.php in the gallery module; the iden field in the (12) update_file and (13) del_file functions in (d) index.php in the downloads module; and other unspecified vectors.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-3814
Credits & Attribution
No credits recorded in the NVD database.
References
- http://osvdb.org/41722
- http://osvdb.org/41721
- http://osvdb.org/41723
- http://www.securityfocus.com/bid/24886
- http://www.securityfocus.com/archive/1/473495/100/0/threaded
- http://www.securityfocus.com/bid/24891
- https://www.exploit-db.com/exploits/4179
- http://securityreason.com/securityalert/2894
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35391
- http://osvdb.org/41719
- http://osvdb.org/41720
More from mkportal
View All →Affected Vendor
mkportal
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.