SQL Injection Vulnerability in e-Vision CMS by e-Vision Technologies
CVE-2007-3214

Currently unrated

Key Information:

Vendor

E-vision

Vendor
CVE Published:
14 June 2007

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2007-3214?

An SQL injection vulnerability exists in style.php of e-Vision CMS versions 2.02 and earlier, which may lead to unauthorized execution of SQL commands. This flaw occurs when 'magic_quotes_gpc' is disabled, enabling remote attackers to manipulate the template parameter and gain access to sensitive data within the database.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.