Unrated severityNVD Advisory· Published Jun 26, 2007· Updated Apr 23, 2026
CVE-2007-3399
CVE-2007-3399
Description
SQL injection vulnerability in include/get_userdata.php in Power Phlogger (PPhlogger) 2.2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter to login.php.
Affected products
5cpe:2.3:a:phpee:power_phlogger:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:phpee:power_phlogger:*:*:*:*:*:*:*:*range: <=2.2.5
- cpe:2.3:a:phpee:power_phlogger:2.2.2:alpha:*:*:*:*:*:*
- cpe:2.3:a:phpee:power_phlogger:2.2.2:beta:*:*:*:*:*:*
- cpe:2.3:a:phpee:power_phlogger:2.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:phpee:power_phlogger:2.2.4:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- securityreason.com/securityalert/2833nvdExploit
- www.vupen.com/english/advisories/2007/2433nvdVendor Advisory
- osvdb.org/38229nvd
- osvdb.org/38944nvd
- www.securityfocus.com/archive/1/472199/100/0/threadednvd
- www.securityfocus.com/bid/24622nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/35043nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/35258nvd
News mentions
0No linked articles in our index yet.