VYPR
Unrated severityNVD Advisory· Published Sep 11, 2007· Updated Jun 16, 2026

CVE-2007-4808

CVE-2007-4808

Description

Multiple SQL injection vulnerabilities in TLM CMS 3.2 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to news.php in a lirenews action, (2) the idnews parameter to goodies.php in a lire action, (3) the id parameter to file.php in a voir action, (4) the ID parameter to affichage.php, (5) the id_sal parameter to mod_forum/afficher.php, or (6) the id_sujet parameter to mod_forum/messages.php. NOTE: it was later reported that goodies.php and affichage.php scripts are reachable through index.php, and 1.1 is also affected. NOTE: it was later reported that the goodies.php vector also affects 3.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Tlm CMS/CMS3 versions
    cpe:2.3:a:tlm_cms:tlm_cms:1.1:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:tlm_cms:tlm_cms:1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:tlm_cms:tlm_cms:3.2:*:*:*:*:*:*:*
    • (no CPE)range: <=3.2, 1.1, 3.1

Patches

Vulnerability mechanics

References

14

News mentions

0

No linked articles in our index yet.