First published: Thu Jul 05 2007(Updated: )
SQL injection vulnerability in viewforum.php in PNphpBB2 1.2i and earlier for Postnuke allows remote attackers to execute arbitrary SQL commands via the order parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Postnuke Software Foundation Pnphpbb2 | <=1.2i |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3584 is considered to be of high severity due to the possibility of remote SQL injection attacks.
To fix CVE-2007-3584, you should upgrade to a later version of PNphpBB2 that is not vulnerable to SQL injection.
Exploitation of CVE-2007-3584 allows an attacker to execute arbitrary SQL commands, potentially compromising the database.
CVE-2007-3584 affects PNphpBB2 version 1.2i and earlier.
CVE-2007-3584 is an SQL injection vulnerability that can be exploited through the order parameter in viewforum.php.