CVE-2007-0388: SQL Injection
SQL injection vulnerability in search.php in Woltlab Burning Board (wBB) 1.0.2 and earlier, and 2.3.6 and earlier in the 2.x series, allows remote attackers to execute arbitrary SQL commands via the boardids[1] and other boardids[] parameters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-0388?
CVE-2007-0388 is considered a high severity vulnerability due to its potential for remote SQL command execution.
How do I fix CVE-2007-0388?
To fix CVE-2007-0388, upgrade to at least WoltLab Burning Board version 2.3.7 or later, which contains the necessary patches.
What versions of WoltLab Burning Board are affected by CVE-2007-0388?
CVE-2007-0388 affects WoltLab Burning Board versions 1.0.2 and earlier, as well as 2.3.6 and earlier in the 2.x series.
Can CVE-2007-0388 be exploited remotely?
Yes, CVE-2007-0388 can be exploited remotely by attackers manipulating the boardids[] parameters.
What are the potential consequences of exploiting CVE-2007-0388?
Exploiting CVE-2007-0388 could allow an attacker to execute arbitrary SQL commands, potentially leading to data loss or unauthorized access.