CVE-2007-2911: SQL Injection
Published May 30, 2007
·Updated
SQL injection vulnerability in admincp/attachment.php in Jelsoft vBulletin before 3.6.6 allows remote authenticated administrators to execute arbitrary SQL commands via the "Attached After" field (GPC['search']['datelineafter'] variable), a related issue to CVE-2007-1573.
Affected Software
1 affected component
Jelsoft vBulletin<=3.6.5
Remediation
Patch Available
Event History
May 30, 2007
CVE Published
10:30 AM
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2911?
CVE-2007-2911 has a moderate severity level due to the ability for authenticated administrators to execute arbitrary SQL commands.
2
How do I fix CVE-2007-2911?
To fix CVE-2007-2911, upgrade your vBulletin installation to version 3.6.6 or later.
3
What versions of vBulletin are affected by CVE-2007-2911?
CVE-2007-2911 affects vBulletin versions prior to 3.6.6.
4
What type of vulnerability is CVE-2007-2911?
CVE-2007-2911 is an SQL injection vulnerability.
5
Who can exploit CVE-2007-2911?
CVE-2007-2911 can be exploited by remote authenticated administrators.