First published: Fri Jun 15 2007(Updated: )
SQL injection vulnerability in bb-includes/formatting-functions.php in bbPress before 0.8.1 might allow remote attackers to execute arbitrary SQL commands via unspecified vectors to forums/bb-edit.php, as demonstrated by a PRE element, aka the "quircky slashes bug."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
openMairie Openpresse | =0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3244 is classified as a high severity vulnerability due to its potential for remote SQL injection attacks.
To fix CVE-2007-3244, upgrade to bbPress version 0.8.1 or later where the vulnerability has been addressed.
CVE-2007-3244 can allow remote attackers to execute arbitrary SQL commands, potentially compromising the database.
CVE-2007-3244 affects all versions of bbPress prior to 0.8.1.
Systems running bbPress versions 0.8.0 and earlier are primarily at risk from CVE-2007-3244.