CVE-2007-0502: SQL Injection
Published Jan 25, 2007
·Updated
SQL injection vulnerability in gallery.php in webSPELL 4.01.02 allows remote attackers to execute arbitrary SQL commands via the picID parameter, a different vector than CVE-2007-0492.
Affected Software
1 affected component
webSPELL Webspell=4.01.02
Event History
Jan 25, 2007
CVE Published
09:28 PM
Jan 26, 2007
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-0502?
CVE-2007-0502 is classified as a medium severity SQL injection vulnerability.
2
How do I fix CVE-2007-0502?
To fix CVE-2007-0502, update webSPELL to a version that addresses this SQL injection issue.
3
What software is affected by CVE-2007-0502?
CVE-2007-0502 affects webSPELL version 4.01.02.
4
Can CVE-2007-0502 allow unauthorized access to my database?
Yes, CVE-2007-0502 can allow attackers to execute arbitrary SQL commands, potentially leading to unauthorized access.
5
What is the impact of exploiting CVE-2007-0502?
Exploiting CVE-2007-0502 can lead to data manipulation, data exfiltration, or complete database compromise.