First published: Tue Sep 04 2007(Updated: )
SQL injection vulnerability in links.php in the Links MOD 1.2.2 and earlier for phpBB 2.0.22 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter in a search action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpBB | <=2.0.22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4653 is considered a critical vulnerability due to its potential for remote SQL injection, which can lead to unauthorized access to sensitive data.
To fix CVE-2007-4653, upgrade to a version of phpBB that is later than 2.0.22 which does not include the vulnerability.
CVE-2007-4653 affects Links MOD 1.2.2 and earlier for phpBB version 2.0.22 and earlier.
Yes, CVE-2007-4653 can be exploited by unauthenticated users through crafted search actions.
Exploiting CVE-2007-4653 can allow attackers to execute arbitrary SQL commands, potentially compromising the database and leaking sensitive information.