First published: Sat Feb 03 2007(Updated: )
Multiple SQL injection vulnerabilities in ACGVannu 1.3 and earlier allow remote attackers to execute arbitrary SQL commands via the id_mod parameter to templates/modif.html, and other unspecified vectors. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mentiss Acgv Acgvannu | <=1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0698 is rated as a medium severity vulnerability due to its potential to allow remote attackers to execute arbitrary SQL commands.
To fix CVE-2007-0698, it is recommended to upgrade to a version of ACGVannu that is greater than 1.3 or apply necessary input validation and sanitization measures.
CVE-2007-0698 affects versions of ACGVannu prior to 1.4, specifically version 1.3 and earlier.
CVE-2007-0698 can facilitate SQL injection attacks, allowing attackers to manipulate database queries.
Exploiting CVE-2007-0698 can lead to unauthorized access to sensitive data, data corruption, or complete compromise of the database.