7.5
CVE-2008-7040
- EPSS 2.8%
- Veröffentlicht 24.08.2009 10:30:01
- Zuletzt bearbeitet 16.06.2026 23:03:28
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Yellow Swordfish Simple Forum <= 1.11 - SQL Injection
SQL injection vulnerability in ahah/sf-profile.php in the Yellow Swordfish Simple Forum module for Wordpress allows remote attackers to execute arbitrary SQL commands via the u parameter. NOTE: this issue was disclosed by an unreliable researcher, so the details might be incorrect.
Mögliche Gegenmaßnahme
Yellow Swordfish Simple Forum: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Yellowswordfish ≫ Simple Forum Version-
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Yellow Swordfish Simple Forum
Version
*-1.11
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.8% | 0.846 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
http://osvdb.org/52210
http://www.securityfocus.com/archive/1/488279
http://www.securityfocus.com/bid/27854
https://exchange.xforce.ibmcloud.com/vulnerabilities/41578
https://www.wordfence.com/threat-intel/vulnerabilities/id/2be3638e-3a0d-40e5-914e-9f20971abf9a