CVE-2007-4966: SQL Injection
Published Sep 18, 2007
·Updated
SQL injection vulnerability in www/people/editprofile.php in GForge 4.6b2 and earlier allows remote attackers to execute arbitrary SQL commands via the skilldelete[] parameter.
Affected Software
1 affected component
GForge<=4.6_b2
Event History
Sep 18, 2007
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-4966?
CVE-2007-4966 is classified as a medium-severity vulnerability due to its potential for SQL injection attacks.
2
How do I fix CVE-2007-4966?
To fix CVE-2007-4966, you should upgrade to GForge version 4.6b3 or later, which addresses the SQL injection issue.
3
What type of attack does CVE-2007-4966 enable?
CVE-2007-4966 enables remote attackers to execute arbitrary SQL commands through the skill_delete[] parameter.
4
In which versions of GForge is CVE-2007-4966 found?
CVE-2007-4966 is found in GForge version 4.6b2 and earlier.
5
Who is affected by CVE-2007-4966?
Users of GForge 4.6b2 and earlier are affected by CVE-2007-4966, particularly those who allow user input in their applications.