{"api_version":"1","generated_at":"2026-07-23T11:29:27+00:00","cve":"CVE-2007-3631","urls":{"html":"https://cve.report/CVE-2007-3631","api":"https://cve.report/api/cve/CVE-2007-3631.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-3631","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-3631"},"summary":{"title":"CVE-2007-3631","description":"SQL injection vulnerability in index.php in GameSiteScript (gss) 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the params parameter, related to missing input validation of the id field.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-07-10 00:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35292","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35292","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/36362","name":"http://osvdb.org/36362","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2007/2460","name":"http://www.vupen.com/english/advisories/2007/2460","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/25983","name":"http://secunia.com/advisories/25983","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"GameSiteScript \"params\" SQL Injection Vulnerability - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/4159","name":"https://www.exploit-db.com/exploits/4159","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"GameSiteScript <= 3.1 (profile id) Remote SQL Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/24807","name":"http://www.securityfocus.com/bid/24807","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"GameSiteScript Index.PHP SQL Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-3631","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-3631","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"3631","vulnerable":"1","versionEndIncluding":"3.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gamesitescript","cpe5":"gamesitescript","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T14:21:36.478Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"24807","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/24807"},{"name":"4159","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/4159"},{"name":"25983","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/25983"},{"name":"36362","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/36362"},{"name":"ADV-2007-2460","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/2460"},{"name":"gamesitescript-params-sql-injection(35292)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35292"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-07-07T00:00:00.000Z","descriptions":[{"lang":"en","value":"SQL injection vulnerability in index.php in GameSiteScript (gss) 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the params parameter, related to missing input validation of the id field."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"24807","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/24807"},{"name":"4159","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/4159"},{"name":"25983","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/25983"},{"name":"36362","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/36362"},{"name":"ADV-2007-2460","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/2460"},{"name":"gamesitescript-params-sql-injection(35292)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35292"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-3631","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"SQL injection vulnerability in index.php in GameSiteScript (gss) 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the params parameter, related to missing input validation of the id field."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"24807","refsource":"BID","url":"http://www.securityfocus.com/bid/24807"},{"name":"4159","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/4159"},{"name":"25983","refsource":"SECUNIA","url":"http://secunia.com/advisories/25983"},{"name":"36362","refsource":"OSVDB","url":"http://osvdb.org/36362"},{"name":"ADV-2007-2460","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/2460"},{"name":"gamesitescript-params-sql-injection(35292)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35292"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-3631","datePublished":"2007-07-10T00:00:00.000Z","dateReserved":"2007-07-09T00:00:00.000Z","dateUpdated":"2024-08-07T14:21:36.478Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-07-10 00:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gamesitescript:gamesitescript:*:*:*:*:*:*:*:*","versionEndIncluding":"3.1","matchCriteriaId":"C5929DA3-F5F7-4A2D-9EA2-3A66053E8B84"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"3631","Ordinal":"1","Title":"CVE-2007-3631","CVE":"CVE-2007-3631","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"3631","Ordinal":"1","NoteData":"SQL injection vulnerability in index.php in GameSiteScript (gss) 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the params parameter, related to missing input validation of the id field.","Type":"Description","Title":"CVE-2007-3631"},{"CveYear":"2007","CveId":"3631","Ordinal":"2","NoteData":"2007-07-09","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"3631","Ordinal":"3","NoteData":"2017-09-28","Type":"Other","Title":"Modified"}]}}}