ZeroHour

CVE-2017-7290

PoC
CVSS 3.0
7.2 high
EPSS
2%p82
Published
()
Modified
Description

SQL injection vulnerability in XOOPS 2.5.7.2 and other versions before 2.5.8.1 allows remote authenticated administrators to execute arbitrary SQL commands via the url parameter to findusers.php. An example attack uses "into outfile" to create a backdoor program.

Vendors
xoops
Products
xoops
Weakness
CWE-89
Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.