Unrated severityNVD Advisory· Published Jan 11, 2007· Updated Apr 23, 2026
CVE-2007-0202
CVE-2007-0202
Description
SQL injection vulnerability in index.php in @lex Guestbook 4.0.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the lang parameter.
Affected products
4cpe:2.3:a:alexphpteam:alex_guestbook:3.12:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:alexphpteam:alex_guestbook:3.12:*:*:*:*:*:*:*
- cpe:2.3:a:alexphpteam:alex_guestbook:3.13:*:*:*:*:*:*:*
- cpe:2.3:a:alexphpteam:alex_guestbook:4.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:alexphpteam:alex_guestbook:4.0.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- acid-root.new.fr/poc/20070107.txtnvdExploit
- secunia.com/advisories/23637nvdVendor Advisory
- osvdb.org/31707nvd
- securityreason.com/securityalert/2135nvd
- www.securityfocus.com/archive/1/456218/100/0/threadednvd
- www.securityfocus.com/bid/21926nvd
- www.vupen.com/english/advisories/2007/0137nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/31393nvd
- www.exploit-db.com/exploits/3103nvd
News mentions
0No linked articles in our index yet.