CVE-2007-1292: SQL Injection
SQL injection vulnerability in inlinemod.php in Jelsoft vBulletin before 3.5.8, and before 3.6.5 in the 3.6.x series, might allow remote authenticated users to execute arbitrary SQL commands via the postids parameter. NOTE: the vendor states that the attack is feasible only in circumstances "almost impossible to achieve."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1292?
CVE-2007-1292 is classified as a moderate severity vulnerability that can allow remote authenticated users to execute arbitrary SQL commands.
How do I fix CVE-2007-1292?
To fix CVE-2007-1292, you should upgrade your vBulletin installation to version 3.5.8 or later.
Which versions are affected by CVE-2007-1292?
CVE-2007-1292 affects all vBulletin versions prior to 3.5.8 and 3.6.5 for the 3.6.x series.
Is CVE-2007-1292 exploitable remotely?
Yes, CVE-2007-1292 can be exploited by remote authenticated users.
What type of vulnerability is CVE-2007-1292?
CVE-2007-1292 is an SQL injection vulnerability.