CVE-2007-2599 describes multiple SQL injection vulnerabilities in TutorialCMS (aka Photoshop Tutorials) version 1.00 and earlier. These flaws allow remote attackers to execute arbitrary SQL commands through various parameters in several PHP scripts, including browseCat.php, browseSubCat.php, openTutorial.php, topFrame.php, admin/editListing.php, and search.php. The vulnerability carries a CVSS score of 7.5, indicating high severity due to its network-based attack vector, low attack complexity, and potential for partial compromise of confidentiality, integrity, and availability. This means an unauthenticated attacker could easily exploit these flaws to access, modify, or delete database content. While not listed on the KEV catalog or Metasploit, an exploit for the 'search.php?search' parameter is publicly available on ExploitDB. Despite this, there is no evidence of active exploitation, and the vulnerability has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.00CPE matchmatch criteria | cpe:2.3:a:wavelink_media:tutorialcms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.