Multiple SQL injection vulnerabilities in Kalptaru Infotech Ltd. Star Articles...
Vulnerability Description
Multiple SQL injection vulnerabilities in Kalptaru Infotech Ltd. Star Articles 6.0 allow remote attackers to inject arbitrary SQL commands via (1) the subcatid parameter to article.list.php; or the artid parameter to (2) article.print.php, (3) article.comments.php, (4) article.publisher.php, or (5) article.download.php; and (6) the PATH_INFO to article.download.php. NOTE: some of these details are obtained from third party information.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-7075
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.exploit-db.com/exploits/7240
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46981
- http://www.vupen.com/english/advisories/2008/3269
- http://www.securityfocus.com/bid/32489
- https://www.exploit-db.com/exploits/7243
- http://secunia.com/advisories/32887
- http://osvdb.org/50455
- http://osvdb.org/50453
- http://osvdb.org/50454
- http://osvdb.org/50452
- http://osvdb.org/50456
More from kalptaru infotech
View All →Affected Vendor
kalptaru infotech
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.