CVE-2007-5177: SQL Injection
Published Oct 3, 2007
·Updated
SQL injection vulnerability in index.php in the MambAds (commambads) 1.5 and earlier component for Mambo allows remote attackers to execute arbitrary SQL commands via the caid parameter.
Affected Software
2 affected components
Mambo Mambo
MambAds MambAds<=1.5
Event History
Oct 3, 2007
CVE Published
02:17 PM
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-5177?
CVE-2007-5177 has a medium severity level due to its potential for executing arbitrary SQL commands.
2
How do I fix CVE-2007-5177?
To fix CVE-2007-5177, update the MambAds component to a secure version beyond 1.5.
3
Who is affected by CVE-2007-5177?
CVE-2007-5177 affects users running MambAds component version 1.5 and earlier on Mambo.
4
What types of attacks can CVE-2007-5177 facilitate?
CVE-2007-5177 can facilitate SQL injection attacks allowing remote attackers to manipulate the database.
5
What applications are related to CVE-2007-5177?
CVE-2007-5177 is related to the MambAds component for Mambo applications.