HIGH
SQL injection vulnerability in philboard_forum.asp in husrevforum 1.0.1 allows remote attackers to execute arbitrary SQL commands via the forumid parameter
Published Jul 18, 2007
7.5
HIGHCVSS 2.0
EPSS 1.87%
Description
SQL injection vulnerability in philboard_forum.asp in husrevforum 1.0.1 allows remote attackers to execute arbitrary SQL commands via the forumid parameter. NOTE: it was later reported that 2.0.1 is also affected.
Affected products
No data.
OR
- 1.0.1
- 2.0.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (9)
- http://secunia.com/advisories/26089 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/26736 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.osvdb.org/38185 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/archive/1/478974/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/24928 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2007/2557 vdb-entryx_refsource_VUPENVendor Advisory
- http://yollubunlar.org/husrev-forums-v201powerboard-sql-injection-exploit-3503.html x_refsource_MISC
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35443 vdb-entryx_refsource_XF
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36530 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://secunia.com/advisories/26089 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://secunia.com/advisories/26736 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://www.osvdb.org/38185 | vdb-entryx_refsource_OSVDB | |
| http://www.securityfocus.com/archive/1/478974/100/0/threaded | mailing-listx_refsource_BUGTRAQ | |
| http://www.securityfocus.com/bid/24928 | vdb-entryx_refsource_BID | |
| http://www.vupen.com/english/advisories/2007/2557 | vdb-entryx_refsource_VUPENVendor Advisory | |
| http://yollubunlar.org/husrev-forums-v201powerboard-sql-injection-exploit-3503.html | x_refsource_MISC | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/35443 | vdb-entryx_refsource_XF | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/36530 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 18, 2007
Updated Aug 7, 2024
Reserved Jul 18, 2007
Link CVE-2007-3884
CISA Vulnrichment
Updated n/a