CVE-2007-6127 | project alumni up to 1.0.8 view.page.inc.php year sql injection (EDB-4655 / XFDB-38620)
A vulnerability classified as critical was found in project alumni up to 1.0.8. Affected by this vulnerability is an unknown functionality of the file view.page.inc.php. The manipulation of the argument year leads to sql injection.
This vulnerability is known as CVE-2007-6127. The attack can be launched remotely. Furthermore, there is an exploit available.