First published: Thu Jun 21 2007(Updated: )
SQL injection vulnerability in print.php in the Articles 1.02 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xoops Article Module | <=1.02 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3311 is considered a critical vulnerability due to its potential for arbitrary SQL command execution.
To fix CVE-2007-3311, upgrade the Xoops Articles Module to a version later than 1.02.
CVE-2007-3311 affects the Xoops Articles Module version 1.02 and earlier.
CVE-2007-3311 exploits occur when an attacker manipulates the 'id' parameter in print.php, leading to arbitrary SQL commands being executed.
The potential impacts of CVE-2007-3311 include data leakage, database manipulation, and full system compromise.