SQL injection vulnerability in functions/functions_filters.asp in Web Wiz Forums before...
Vulnerability Description
SQL injection vulnerability in functions/functions_filters.asp in Web Wiz Forums before 8.05a (MySQL version) does not properly filter certain characters in SQL commands, which allows remote attackers to execute arbitrary SQL commands via \"' (backslash double-quote quote) sequences, which are collapsed into \'', as demonstrated via the name parameter to forum/pop_up_member_search.asp.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-1548
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/bid/23051
- http://secunia.com/advisories/24561
- http://www.vupen.com/english/advisories/2007/1061
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33095
- http://www.webwizguide.info/web_wiz_forums/Version%20History.txt
- http://www.securityfocus.com/archive/1/463287/100/0/threaded
- http://securityreason.com/securityalert/2456
- http://osvdb.org/34344
- http://ifsec.blogspot.com/2007/03/web-wiz-forums-805-mysql-version-sql.html
More from webwizguide
View All →Affected Vendor
webwizguide
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.