CVE-2007-4112
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/07/2007
Last modified:
09/04/2025
Description
Multiple SQL injection vulnerabilities in Advanced Webhost Billing System (AWBS) before 2.6.0, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: this can be leveraged for XSS attacks that "bypass AWBS's anti-XSS input validation."
Impact
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:advanced_webhost_billing_system:advanced_webhost_billing_system:*:*:*:*:*:*:*:* | 2.5.1 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://osvdb.org/37257
- http://secunia.com/advisories/26214
- http://www.justinsamuel.com/2007/06/10/awbs-magic_quotes_gpc-off-sql-injection-and-xss-vulnerabilities/
- http://www.securityfocus.com/bid/25089
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46160
- http://osvdb.org/37257
- http://secunia.com/advisories/26214
- http://www.justinsamuel.com/2007/06/10/awbs-magic_quotes_gpc-off-sql-injection-and-xss-vulnerabilities/
- http://www.securityfocus.com/bid/25089
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46160