LIVE NEWSROOM · --:-- · May 24, 2026
A LIBRARY FOR SECURITY RESEARCHERS

CVE DATABASE  /  CVE-2007-6602

CVE-2007-6602

CVSS 7.5 · HIGH

Summary

SQL injection vulnerability in app/models/identity.php in NoseRub 0.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the username field to the login script.

CVSS 2.0 breakdown

Base score7.5 (HIGH)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Attack vectorNETWORK
Attack complexityLOW
ConfidentialityPARTIAL
IntegrityPARTIAL
AvailabilityPARTIAL

Weakness type (CWE)

Affected products

Noserub noserub
Check this CVE live

Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.

References

Data: NIST NVD. NVD last modified 2026-04-23. Always verify against the vendor advisory before acting.

Scroll to Top