2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2007-1548" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2007-03-20T22:19:00.000" ,
2024-11-22 03:16:05 +00:00
"lastModified" : "2024-11-21T00:28:35.553" ,
2023-04-24 12:24:31 +02:00
"vulnStatus" : "Modified" ,
2024-12-08 03:06:42 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "SQL injection vulnerability in functions/functions_filters.asp in Web Wiz Forums before 8.05a (MySQL version) does not properly filter certain characters in SQL commands, which allows remote attackers to execute arbitrary SQL commands via \\\"' (backslash double-quote quote) sequences, which are collapsed into \\'', as demonstrated via the name parameter to forum/pop_up_member_search.asp."
} ,
{
"lang" : "es" ,
"value" : "Una vulnerabilidad de inyecci\u00f3n SQL en el archivo functions/functions_filters.asp en Web Wiz Forums anterior a la versi\u00f3n 8.05a (versi\u00f3n MySQL) no filtra apropiadamente ciertos caracteres en los comandos SQL, lo que permite a los atacantes remotos ejecutar comandos SQL arbitrarios por medio de la secuencia \\\"' (barra invertida-comillas dobles), que se contraen en \\'', como se muestra por medio del par\u00e1metro name en forum/pop_up_member_search.asp."
}
] ,
"metrics" : {
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P" ,
2024-11-22 03:16:05 +00:00
"baseScore" : 7.5 ,
2023-04-24 12:24:31 +02:00
"accessVector" : "NETWORK" ,
"accessComplexity" : "LOW" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "PARTIAL" ,
"integrityImpact" : "PARTIAL" ,
2024-11-22 03:16:05 +00:00
"availabilityImpact" : "PARTIAL"
2023-04-24 12:24:31 +02:00
} ,
"baseSeverity" : "HIGH" ,
"exploitabilityScore" : 10.0 ,
"impactScore" : 6.4 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : true ,
"userInteractionRequired" : false
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-89"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "8.05" ,
"matchCriteriaId" : "D60452E2-7B96-44DC-B0BD-3C2C624F1E92"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:5.21:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C570D39D-114E-41AB-A7A9-4389CA4D0735"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:5.22:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9EEB8308-1A8C-4495-A5BD-6D6F321C84B4"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:6:beta_1:*:*:*:*:*:*" ,
"matchCriteriaId" : "E5F41195-D3B0-42E0-8490-8556EF939FBD"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:6:beta_2:*:*:*:*:*:*" ,
"matchCriteriaId" : "FBB04952-D7EA-411E-97EB-71CC9D0AA21E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:6:beta_3:*:*:*:*:*:*" ,
"matchCriteriaId" : "381D4A63-E3D1-42D4-AE25-70523C1D7AEB"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:6:beta_4:*:*:*:*:*:*" ,
"matchCriteriaId" : "AC4FC5DE-F661-48A6-99DC-90BE1E6B683E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:6:beta_5:*:*:*:*:*:*" ,
"matchCriteriaId" : "9CA02A0D-82F6-4E7A-B77B-23C47E9AA15D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:6:beta_6:*:*:*:*:*:*" ,
"matchCriteriaId" : "85865444-6F19-4A21-AD91-D572D2D0129E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:6.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "619FD257-B6FF-4E37-91E1-9C3CA3C6A4F0"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:6.10:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "658FB7FB-7003-4003-81AD-799F171DFC36"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:6.11:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E211F91A-5255-4146-A270-ABC1A204AAE8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:6.12:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "15489B55-722E-4605-B0CB-EA0F4BEF422B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:6.20:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B933FD9C-2AE3-4E3E-A1DB-E23314D51FE2"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:6.21:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "62605E2E-3720-45F6-8092-2BAEC548C10C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:6.22:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "59FD4A03-EBC9-466B-9956-360C92F9B3C4"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:6.23:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B9B0616C-DA43-4688-B396-1F7D915D8106"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:6.24:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D42135EA-E5B7-410C-AEA0-91E4D2BF9D0B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:6.25:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D97A143D-043C-4F20-BA86-4102727A908B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:6.26:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "44718687-CC3C-43A5-AAB3-784CC6F91489"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:6.27:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7433F60B-4BFC-434A-AF52-407547A9D5A8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:6.28:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C0CB2CC7-0C42-4CD3-BF15-E0CA57567B0B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:6.29:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4CF74835-B33A-465B-A28A-4D45EB900653"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:6.30:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "64EF4588-262A-4064-8366-CDD692EEA4B8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:6.32:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "80330E0F-D686-4581-A2CF-A2E6F68B4C55"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:6.33:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7796749E-58CA-49AC-BF5E-EE1075CE50E5"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:6.34:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "BF3473DF-F00F-4406-9D3E-6A8E0361E7B6"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:7:beta_4:*:*:*:*:*:*" ,
"matchCriteriaId" : "177B6CF4-04C6-4096-9AB4-F99B282228D9"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:7:rc1:*:*:*:*:*:*" ,
"matchCriteriaId" : "5769B294-1CE5-4317-B408-573C040805B4"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:7.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A6DBC28F-9E00-431E-9F66-F16482AC839A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:7.01:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9952614D-2E2C-4C29-92A4-897F2F1E324B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:7.5:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D9DAD04A-724F-4E21-A1F9-86309D1B8FB0"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:7.5:beta_1:*:*:*:*:*:*" ,
"matchCriteriaId" : "E8071F07-6618-4C80-8172-BEA24A2B5408"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:7.6:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "204A4546-BC27-4B85-8AF7-01C8B003625A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:7.7:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3D631B87-1527-4976-A8A4-E33279561AA9"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:7.7a:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "34C76CAC-2854-4511-87FA-75946ABD81F0"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:7.8:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "BE8E9F96-EF9D-4EF6-9058-DA17E42928E8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:7.9:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "DE3095A5-B7D0-4FCD-96AE-0F8B55398A9A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:7.51:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B5AC122B-1B97-4E51-9E0A-9C8DB4FDA23D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:7.51a:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F1BB56D4-ADB2-4BED-825B-12A08BED0F7E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:7.92:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7FB93AA4-452F-4449-AB36-EA1AA4EB95F1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:7.95:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "DE82C94C-7A5A-4CCD-93DE-B6766BB702E3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:7.96:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8AF3BD34-2F75-4165-982B-12F9B277FF06"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:8:beta_1:*:*:*:*:*:*" ,
"matchCriteriaId" : "AB43F534-5ABD-467C-B960-76E7167ADA73"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:8:beta_2:*:*:*:*:*:*" ,
"matchCriteriaId" : "F2BD800A-FD05-4049-AD60-9A63A229BE3B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:8:rc1:*:*:*:*:*:*" ,
"matchCriteriaId" : "F882478C-0E32-4798-8A35-D04266D829E3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:8:rc1.1:*:*:*:*:*:*" ,
"matchCriteriaId" : "73326579-D007-4951-AD9F-65DB1A36D265"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:8.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CD181851-0B7A-4397-866C-E352701E4E3F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:8.01:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E5907FDD-2642-4FC5-B91A-FF7E515B6422"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:8.02:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A52CF51A-C1AB-445E-9B73-ECE88BBAB817"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:8.03:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "17A1F6D4-EE6E-43BE-8952-D66F0D0DAEBC"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webwizguide:web_wiz_forums:8.04:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C3E1A3FA-C5E6-4F99-9CB2-1721353E06BC"
}
]
}
]
}
] ,
"references" : [
{
"url" : "http://ifsec.blogspot.com/2007/03/web-wiz-forums-805-mysql-version-sql.html" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Exploit"
]
} ,
2024-04-04 08:46:00 +00:00
{
"url" : "http://osvdb.org/34344" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "http://secunia.com/advisories/24561" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Vendor Advisory"
]
} ,
2023-04-24 12:24:31 +02:00
{
"url" : "http://securityreason.com/securityalert/2456" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Exploit"
]
} ,
{
"url" : "http://www.securityfocus.com/archive/1/463287/100/0/threaded" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "http://www.securityfocus.com/bid/23051" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Exploit"
]
} ,
{
"url" : "http://www.vupen.com/english/advisories/2007/1061" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Vendor Advisory"
]
} ,
2024-04-04 08:46:00 +00:00
{
"url" : "http://www.webwizguide.info/web_wiz_forums/Version%20History.txt" ,
"source" : "cve@mitre.org"
} ,
2023-04-24 12:24:31 +02:00
{
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/33095" ,
"source" : "cve@mitre.org"
2024-11-22 03:16:05 +00:00
} ,
{
"url" : "http://ifsec.blogspot.com/2007/03/web-wiz-forums-805-mysql-version-sql.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Exploit"
]
} ,
{
"url" : "http://osvdb.org/34344" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://secunia.com/advisories/24561" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "http://securityreason.com/securityalert/2456" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Exploit"
]
} ,
{
"url" : "http://www.securityfocus.com/archive/1/463287/100/0/threaded" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://www.securityfocus.com/bid/23051" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Exploit"
]
} ,
{
"url" : "http://www.vupen.com/english/advisories/2007/1061" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "http://www.webwizguide.info/web_wiz_forums/Version%20History.txt" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/33095" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
2023-04-24 12:24:31 +02:00
}
]
}