Title : IndexScript "cat_id" Parameter Processing Remote SQL Injection Vulnerability VUPEN ID : VUPEN/ADV-2007-2696 CVE ID : CVE-2007-4069
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-07-30
Technical Description
A vulnerability has been identified in IndexScript, which could be exploited by attackers to execute arbitrary SQL queries. This issue is caused by an input validation error in the "show_cat.php" script that does not validate the "cat_id" parameter before being used in SQL statements, which could be exploited by malicious people to conduct SQL injection attacks.