First published: Wed Apr 11 2007(Updated: )
SQL injection vulnerability in index.php in the WF-Snippets 1.02 and earlier module for XOOPS allows remote attackers to execute arbitrary SQL commands via the c parameter in a cat action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xoops Wf-snippets | <=1.02 | |
E-xoops |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1962 is considered a medium severity SQL injection vulnerability.
To fix CVE-2007-1962, upgrade to WF-Snippets version 1.03 or later.
CVE-2007-1962 affects WF-Snippets versions 1.02 and earlier running on the XOOPS platform.
CVE-2007-1962 allows remote attackers to execute arbitrary SQL commands.
More information about CVE-2007-1962 can be obtained from security advisory databases.