Unrated severityNVD Advisory· Published Sep 11, 2007· Updated Jun 16, 2026
CVE-2007-4808
CVE-2007-4808
Description
Multiple SQL injection vulnerabilities in TLM CMS 3.2 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to news.php in a lirenews action, (2) the idnews parameter to goodies.php in a lire action, (3) the id parameter to file.php in a voir action, (4) the ID parameter to affichage.php, (5) the id_sal parameter to mod_forum/afficher.php, or (6) the id_sujet parameter to mod_forum/messages.php. NOTE: it was later reported that goodies.php and affichage.php scripts are reachable through index.php, and 1.1 is also affected. NOTE: it was later reported that the goodies.php vector also affects 3.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
14- www.securityfocus.com/bid/25602nvdExploit
- secunia.com/advisories/26752nvdVendor Advisory
- www.vupen.com/english/advisories/2007/3137nvdVendor Advisory
- osvdb.org/37001nvd
- osvdb.org/37002nvd
- osvdb.org/37003nvd
- osvdb.org/37004nvd
- osvdb.org/37005nvd
- osvdb.org/37006nvd
- www.securityfocus.com/bid/29049nvd
- www.z0rlu.ownspace.org/index.phpnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/36536nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/42204nvd
- www.exploit-db.com/exploits/4376nvd
News mentions
0No linked articles in our index yet.