7.5
CVE-2007-0388
- EPSS 1.04%
- Veröffentlicht 19.01.2007 23:28:00
- Zuletzt bearbeitet 16.06.2026 22:35:28
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
SQL injection vulnerability in search.php in Woltlab Burning Board (wBB) 1.0.2 and earlier, and 2.3.6 and earlier in the 2.x series, allows remote attackers to execute arbitrary SQL commands via the boardids[1] and other boardids[] parameters.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Woltlab ≫ Burning Board Version <= 1.0.2
Woltlab ≫ Burning Board Version <= 2.3.6
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.04% | 0.594 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://osvdb.org/33872
https://exchange.xforce.ibmcloud.com/vulnerabilities/31550
https://www.exploit-db.com/exploits/3143
https://www.exploit-db.com/exploits/3144