CVE
- Id
- 28413
- CVE No.
- CVE-2007-5056
- Status
- Candidate
- Description
- Eval injection vulnerability in adodb-perf-module.inc.php in ADOdb Lite 1.42 and earlier, as used in products including CMS Made Simple, SAPID CMF, Journalness, PacerCMS, and Open-Realty, allows remote attackers to execute arbitrary code via PHP sequences in the last_module parameter.
- Phase
- Assigned (20070924)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
295230 | 28413 | CVE-2007-5056 | MILW0RM:4442 | View |
295231 | 28413 | CVE-2007-5056 | URL:http://www.milw0rm.com/exploits/4442 | View |
295232 | 28413 | CVE-2007-5056 | MILW0RM:5090 | View |
295233 | 28413 | CVE-2007-5056 | URL:http://www.milw0rm.com/exploits/5090 | View |
295234 | 28413 | CVE-2007-5056 | MILW0RM:5091 | View |
295235 | 28413 | CVE-2007-5056 | URL:http://www.milw0rm.com/exploits/5091 | View |
295236 | 28413 | CVE-2007-5056 | MILW0RM:5097 | View |
295237 | 28413 | CVE-2007-5056 | URL:http://www.milw0rm.com/exploits/5097 | View |
295238 | 28413 | CVE-2007-5056 | MILW0RM:5098 | View |
295239 | 28413 | CVE-2007-5056 | URL:http://www.milw0rm.com/exploits/5098 | View |
295240 | 28413 | CVE-2007-5056 | VIM:20070924 CMS Made Simple eval injection is really an ADOdb Lite problem | View |
295241 | 28413 | CVE-2007-5056 | URL:http://www.attrition.org/pipermail/vim/2007-September/001800.html | View |
295242 | 28413 | CVE-2007-5056 | BID:25768 | View |
295243 | 28413 | CVE-2007-5056 | URL:http://www.securityfocus.com/bid/25768 | View |
295244 | 28413 | CVE-2007-5056 | OSVDB:41422 | View |
295245 | 28413 | CVE-2007-5056 | URL:http://osvdb.org/41422 | View |
295246 | 28413 | CVE-2007-5056 | OSVDB:41426 | View |
295247 | 28413 | CVE-2007-5056 | URL:http://osvdb.org/41426 | View |
295248 | 28413 | CVE-2007-5056 | OSVDB:41427 | View |
295249 | 28413 | CVE-2007-5056 | URL:http://osvdb.org/41427 | View |
295250 | 28413 | CVE-2007-5056 | OSVDB:41428 | View |
295251 | 28413 | CVE-2007-5056 | URL:http://osvdb.org/41428 | View |
295252 | 28413 | CVE-2007-5056 | VUPEN:ADV-2007-3261 | View |
295253 | 28413 | CVE-2007-5056 | URL:http://www.vupen.com/english/advisories/2007/3261 | View |
295254 | 28413 | CVE-2007-5056 | OSVDB:40596 | View |
295255 | 28413 | CVE-2007-5056 | URL:http://osvdb.org/40596 | View |
295256 | 28413 | CVE-2007-5056 | SECUNIA:26928 | View |
295257 | 28413 | CVE-2007-5056 | URL:http://secunia.com/advisories/26928 | View |
295258 | 28413 | CVE-2007-5056 | SECUNIA:28859 | View |
295259 | 28413 | CVE-2007-5056 | URL:http://secunia.com/advisories/28859 | View |
295260 | 28413 | CVE-2007-5056 | SECUNIA:28873 | View |
295261 | 28413 | CVE-2007-5056 | URL:http://secunia.com/advisories/28873 | View |
295262 | 28413 | CVE-2007-5056 | SECUNIA:28874 | View |
295263 | 28413 | CVE-2007-5056 | URL:http://secunia.com/advisories/28874 | View |
295264 | 28413 | CVE-2007-5056 | SECUNIA:28886 | View |
295265 | 28413 | CVE-2007-5056 | URL:http://secunia.com/advisories/28886 | View |
295266 | 28413 | CVE-2007-5056 | XF:cmsmadesimple-adodbperfmod-code-execution(36733) | View |
295267 | 28413 | CVE-2007-5056 | URL:http://xforce.iss.net/xforce/xfdb/36733 | View |
295268 | 28413 | CVE-2007-5056 | XF:journalness-lastmodule-code-execution(40393) | View |
295269 | 28413 | CVE-2007-5056 | URL:http://xforce.iss.net/xforce/xfdb/40393 | View |
295270 | 28413 | CVE-2007-5056 | XF:openrealty-lastmodule-code-execution(40395) | View |
295271 | 28413 | CVE-2007-5056 | URL:http://xforce.iss.net/xforce/xfdb/40395 | View |
295272 | 28413 | CVE-2007-5056 | XF:pacercms-lastmodule-code-execution(40389) | View |
295273 | 28413 | CVE-2007-5056 | URL:http://xforce.iss.net/xforce/xfdb/40389 | View |
295274 | 28413 | CVE-2007-5056 | XF:sapidcmf-lastmodule-code-execution(40396) | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
53985 | JVNDB-2007-002677 | Barracuda Spam Firewall の Web 管理インターフェースにおけるクロスサイトスクリプティングの脆弱性 | Barracuda Spam Firewall の Web 管理インターフェースは、Monitor Web Syslog が開いている際にログインを適切に処理しないため、スクリーンがクロスサイトスクリプティングの脆弱性が存在します。 | CVE-2007-5058 | 28413 | 4.3 | http://jvndb.jvn.jp/ja/contents/2007/JVNDB-2007-002677.html | View |