CVE-2007-3549

Properties

Published:
02.07.2007
Updated:
05.07.2007
Patch available:
Severity:
High
CVSS vector:
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Product:
Vastal I-Tech: Buddy Zone

Vulnerability description

SQL injection vulnerability in view_sub_cat.php in Buddy Zone 1.5 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

References:

MILW0RM: http://www.milw0rm.com/exploits/4127
BID: http://www.securityfocus.com/bid/24711