CVE-2007-3196: SQL Injection
SQL injection vulnerability in vBSupport.php in vSupport Integrated Ticket System 3.x.x allows remote attackers to execute arbitrary SQL commands via the ticketid parameter in a showticket action.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3196?
CVE-2007-3196 has been classified with a high severity due to its potential for remote arbitrary SQL command execution.
How do I fix CVE-2007-3196?
To fix CVE-2007-3196, upgrade the vSupport Integrated Ticket System to a version that is not vulnerable, such as any version later than 2.0.0_beta_1.
What types of attacks can exploit CVE-2007-3196?
CVE-2007-3196 can be exploited through SQL injection attacks that utilize the ticketid parameter in the showticket action.
Which software versions are affected by CVE-2007-3196?
CVE-2007-3196 affects the vSupport Integrated Ticket System 3.x.x series, specifically version 2.0.0_beta_1.
Is CVE-2007-3196 a known vulnerability?
Yes, CVE-2007-3196 is a known SQL injection vulnerability that has been documented and reported.