{"api_version":"1","generated_at":"2026-07-23T08:57:48+00:00","cve":"CVE-2007-6373","urls":{"html":"https://cve.report/CVE-2007-6373","api":"https://cve.report/api/cve/CVE-2007-6373.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-6373","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-6373"},"summary":{"title":"CVE-2007-6373","description":"Multiple SQL injection vulnerabilities in GestDown 1.00 Beta allow remote attackers to execute arbitrary SQL commands via the (1) categorie parameter to catdownload.php, or the id parameter to (2) download.php or (3) hitcounter.php.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-12-15 01:46:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-89","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://marc.info/?l=bugtraq&m=119730791316604&w=2","name":"http://marc.info/?l=bugtraq&m=119730791316604&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"'SQL injection - GestDownV1.00Beta' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/26799","name":"http://www.securityfocus.com/bid/26799","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"GESTDOWN Multiple SQL Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38945","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38945","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-6373","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-6373","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"6373","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gestdown","cpe5":"gestdown","cpe6":"1.00_beta","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T16:02:36.438Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"gestdown-multiple-scripts-sql-injection(38945)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38945"},{"name":"20071209 SQL injection - GestDownV1.00Beta","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=119730791316604&w=2"},{"name":"26799","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/26799"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-12-09T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple SQL injection vulnerabilities in GestDown 1.00 Beta allow remote attackers to execute arbitrary SQL commands via the (1) categorie parameter to catdownload.php, or the id parameter to (2) download.php or (3) hitcounter.php."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-07T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"gestdown-multiple-scripts-sql-injection(38945)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38945"},{"name":"20071209 SQL injection - GestDownV1.00Beta","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=119730791316604&w=2"},{"name":"26799","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/26799"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-6373","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple SQL injection vulnerabilities in GestDown 1.00 Beta allow remote attackers to execute arbitrary SQL commands via the (1) categorie parameter to catdownload.php, or the id parameter to (2) download.php or (3) hitcounter.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"gestdown-multiple-scripts-sql-injection(38945)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38945"},{"name":"20071209 SQL injection - GestDownV1.00Beta","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=119730791316604&w=2"},{"name":"26799","refsource":"BID","url":"http://www.securityfocus.com/bid/26799"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-6373","datePublished":"2007-12-15T01:00:00.000Z","dateReserved":"2007-12-14T00:00:00.000Z","dateUpdated":"2024-08-07T16:02:36.438Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-12-15 01:46:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-89","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gestdown:gestdown:1.00_beta:*:*:*:*:*:*:*","matchCriteriaId":"06CBC5AF-B1EA-4ACD-BBC2-3F05F979C86B"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"6373","Ordinal":"1","Title":"CVE-2007-6373","CVE":"CVE-2007-6373","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"6373","Ordinal":"1","NoteData":"Multiple SQL injection vulnerabilities in GestDown 1.00 Beta allow remote attackers to execute arbitrary SQL commands via the (1) categorie parameter to catdownload.php, or the id parameter to (2) download.php or (3) hitcounter.php.","Type":"Description","Title":"CVE-2007-6373"},{"CveYear":"2007","CveId":"6373","Ordinal":"2","NoteData":"2007-12-14","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"6373","Ordinal":"3","NoteData":"2017-08-07","Type":"Other","Title":"Modified"}]}}}