CVE-2007-3052: SQL Injection
Published Jun 6, 2007
·Updated
SQL injection vulnerability in index.php in the PNphpBB2 1.2i and earlier module for PostNuke allows remote attackers to execute arbitrary SQL commands via the c parameter.
Affected Software
1 affected component
Postnuke Software Foundation Pnphpbb<=1.2i
Event History
Jun 6, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-3052?
CVE-2007-3052 has a medium severity rating due to its potential for remote SQL execution.
2
How do I fix CVE-2007-3052?
To fix CVE-2007-3052, upgrade to a version of PNphpBB that is newer than 1.2i, which addresses the SQL injection vulnerability.
3
What systems are affected by CVE-2007-3052?
CVE-2007-3052 affects PNphpBB versions 1.2i and earlier used within PostNuke.
4
Can CVE-2007-3052 be exploited remotely?
Yes, CVE-2007-3052 can be exploited remotely by attackers injecting malicious SQL commands through the c parameter.
5
What kind of attack does CVE-2007-3052 allow?
CVE-2007-3052 allows attackers to execute arbitrary SQL commands, potentially compromising the database.