Multiple SQL injection vulnerabilities in TLM CMS 3.2 allow remote...
Vulnerability Description
Multiple SQL injection vulnerabilities in TLM CMS 3.2 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to news.php in a lirenews action, (2) the idnews parameter to goodies.php in a lire action, (3) the id parameter to file.php in a voir action, (4) the ID parameter to affichage.php, (5) the id_sal parameter to mod_forum/afficher.php, or (6) the id_sujet parameter to mod_forum/messages.php. NOTE: it was later reported that goodies.php and affichage.php scripts are reachable through index.php, and 1.1 is also affected. NOTE: it was later reported that the goodies.php vector also affects 3.1.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-4808
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.z0rlu.ownspace.org/index.php?/archives/74-Powered-by-TLM-CMS-index.php-sql-inj..html
- http://osvdb.org/37001
- http://osvdb.org/37002
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42204
- http://osvdb.org/37005
- https://www.exploit-db.com/exploits/4376
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36536
- http://osvdb.org/37003
- http://secunia.com/advisories/26752
- http://www.securityfocus.com/bid/29049
- http://www.securityfocus.com/bid/25602
- http://www.vupen.com/english/advisories/2007/3137
- http://osvdb.org/37004
- http://osvdb.org/37006
Affected Vendor
tlm cms
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.