First published: Wed Feb 28 2007(Updated: )
SQL injection vulnerability in printview.php in webSPELL 4.01.02 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter, a different vector than CVE-2007-1019, CVE-2006-5388, and CVE-2006-4783.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webspell | <=4.01.02 | |
Webspell | =4.0 | |
Webspell | =4.01.00 | |
Webspell | =4.01.01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1163 is considered a high severity vulnerability due to the potential for remote SQL injection attacks.
To fix CVE-2007-1163, upgrade to webSPELL version 4.01.03 or later, as earlier versions are vulnerable.
CVE-2007-1163 affects webSPELL versions 4.01.02 and earlier, including versions 4.0, 4.01.00, and 4.01.01.
CVE-2007-1163 can be exploited to execute arbitrary SQL commands through the topic parameter in printview.php.
While webSPELL may not be commonly used today, CVE-2007-1163 remains a concern for any installations still running affected versions.