CVE-2007-1962: SQL Injection
Published Apr 11, 2007
·Updated
SQL injection vulnerability in index.php in the WF-Snippets 1.02 and earlier module for XOOPS allows remote attackers to execute arbitrary SQL commands via the c parameter in a cat action.
Affected Software
2 affected components
Xoops WF-Snippets<=1.02
Xoops Xoops
Event History
Apr 11, 2007
CVE Published
10:19 AM
Data Sourced
10:19 AM
DescriptionWeaknessAffected Software
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-1962?
CVE-2007-1962 is considered a medium severity SQL injection vulnerability.
2
How do I fix CVE-2007-1962?
To fix CVE-2007-1962, upgrade to WF-Snippets version 1.03 or later.
3
What systems are affected by CVE-2007-1962?
CVE-2007-1962 affects WF-Snippets versions 1.02 and earlier running on the XOOPS platform.
4
What type of attack does CVE-2007-1962 enable?
CVE-2007-1962 allows remote attackers to execute arbitrary SQL commands.
5
Where can I find more information about CVE-2007-1962?
More information about CVE-2007-1962 can be obtained from security advisory databases.