First published: Thu Jan 25 2007(Updated: )
Multiple SQL injection vulnerabilities in gallery.php in webSPELL 4.01.02 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) galleryID parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webspell | <=4.01.02 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0492 is classified as a high severity vulnerability due to potential SQL injection risks.
To fix CVE-2007-0492, upgrade your webSPELL installation to version 4.01.03 or later.
CVE-2007-0492 affects webSPELL version 4.01.02 and earlier.
The potential impacts of CVE-2007-0492 include unauthorized access to the database and execution of arbitrary SQL commands.
Yes, CVE-2007-0492 can be exploited remotely by attackers through specially crafted requests.