Required CVE Record Information
Description
SQL injection vulnerability in functions/functions_filters.asp in Web Wiz Forums before 8.05a (MySQL version) does not properly filter certain characters in SQL commands, which allows remote attackers to execute arbitrary SQL commands via \"' (backslash double-quote quote) sequences, which are collapsed into \'', as demonstrated via the name parameter to forum/pop_up_member_search.asp.
References 9 Total
- securityfocus.com: 23051 vdb-entry
- secunia.com: 24561 third-party-advisory
- vupen.com: ADV-2007-1061 vdb-entry
- exchange.xforce.ibmcloud.com: webwizforums-popupmember-sql-injection(33095) vdb-entry
- http://www.webwizguide.info/web_wiz_forums/Version%20History.txt
- securityfocus.com: 20070320 Web Wiz Forums 8.05 (MySQL version) SQL Injection mailing-list
- securityreason.com: 2456 third-party-advisory
- osvdb.org: 34344 vdb-entry
- http://ifsec.blogspot.com/2007/03/web-wiz-forums-805-mysql-version-sql.html
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 9 Total
- securityfocus.com: 23051 vdb-entryx_transferred
- secunia.com: 24561 third-party-advisoryx_transferred
- vupen.com: ADV-2007-1061 vdb-entryx_transferred
- exchange.xforce.ibmcloud.com: webwizforums-popupmember-sql-injection(33095) vdb-entryx_transferred
- http://www.webwizguide.info/web_wiz_forums/Version%20History.txt x_transferred
- securityfocus.com: 20070320 Web Wiz Forums 8.05 (MySQL version) SQL Injection mailing-listx_transferred
- securityreason.com: 2456 third-party-advisoryx_transferred
- osvdb.org: 34344 vdb-entryx_transferred
- http://ifsec.blogspot.com/2007/03/web-wiz-forums-805-mysql-version-sql.html x_transferred