Skip to main content
PricingEnterprise
Home/Vulnerabilities/EDB-4794
EDB-4794webappsphpVERIFIED

XZero Community Classifieds 4.95.11 - Local File Inclusion / SQL Injection

Kw3[R]Ln12/26/2007
View on Exploit-DBView Source on GitLab

AI AnalysisPowered by AI

Exploit Code

Exploit code not available in database

View Source on GitLab

Related CVEs (2)

CVE-2007-6567

NONE

Directory traversal vulnerability in index.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pagenam

Directory traversal vulnerability in index.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pagenam...

12/28/2007CWE-22

CVE-2007-6566

NONE

SQL injection vulnerability in post.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to execute arbitrary SQL commands via the subcatid parameter to index.php.

SQL injection vulnerability in post.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to execute arbitrary SQL commands via the subcatid parameter to index.php.

12/28/2007CWE-89

Exploit Information

EDB ID
4794
Type
webapps
Platform
php
Verified
Yes
Published
2007-12-26

Associated CVEs

CVE-2007-6567CVE-2007-6566

Quick Actions

Download RawSearch on Google
Disclaimer: This exploit code is provided for educational and authorized security research purposes only. Use responsibly and only on systems you have permission to test.