Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2007-3691
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-3691

Description:
Multiple SQL injection vulnerabilities in changePW.php in AV Tutorial Script (avtutorial) 1.0, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) userid parameters, a different issue than CVE-2007-3630.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/35487

VIM
  http://attrition.org/pipermail/vim/2007-July/001705.html

SAID
  Secunia Advisory: SA25969

OSVDB
  36298


Return to the previous page.