CVE-2007-3311: SQL Injection
Published Jun 21, 2007
·Updated
SQL injection vulnerability in print.php in the Articles 1.02 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id parameter.
Affected Software
1 affected component
Xoops Articles Module<=1.02
Event History
Jun 21, 2007
CVE Published
10:30 AM
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-3311?
CVE-2007-3311 is considered a critical vulnerability due to its potential for arbitrary SQL command execution.
2
How do I fix CVE-2007-3311?
To fix CVE-2007-3311, upgrade the Xoops Articles Module to a version later than 1.02.
3
What systems are affected by CVE-2007-3311?
CVE-2007-3311 affects the Xoops Articles Module version 1.02 and earlier.
4
How does CVE-2007-3311 exploit occur?
CVE-2007-3311 exploits occur when an attacker manipulates the 'id' parameter in print.php, leading to arbitrary SQL commands being executed.
5
What are the potential impacts of CVE-2007-3311?
The potential impacts of CVE-2007-3311 include data leakage, database manipulation, and full system compromise.