CVE-2007-1548
Summary
| CVE | CVE-2007-1548 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-03-20 22:19:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | SQL injection vulnerability in functions/functions_filters.asp in Web Wiz Forums before 8.05a (MySQL version) does not properly filter certain characters in SQL commands, which allows remote attackers to execute arbitrary SQL commands via \"' (backslash double-quote quote) sequences, which are collapsed into \'', as demonstrated via the name parameter to forum/pop_up_member_search.asp. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Webwizguide | Web Wiz Forums | 5.21 | All | All | All |
| Application | Webwizguide | Web Wiz Forums | 5.22 | All | All | All |
| Application | Webwizguide | Web Wiz Forums | 6 | beta_1 | All | All |
| Application | Webwizguide | Web Wiz Forums | 6 | beta_2 | All | All |
| Application | Webwizguide | Web Wiz Forums | 6 | beta_3 | All | All |
| Application | Webwizguide | Web Wiz Forums | 6 | beta_4 | All | All |
| Application | Webwizguide | Web Wiz Forums | 6 | beta_5 | All | All |
| Application | Webwizguide | Web Wiz Forums | 6 | beta_6 | All | All |
| Application | Webwizguide | Web Wiz Forums | 6.0 | All | All | All |
| Application | Webwizguide | Web Wiz Forums | 6.10 | All | All | All |
| Application | Webwizguide | Web Wiz Forums | 6.11 | All | All | All |
| Application | Webwizguide | Web Wiz Forums | 6.12 | All | All | All |
| Application | Webwizguide | Web Wiz Forums | 6.20 | All | All | All |
| Application | Webwizguide | Web Wiz Forums | 6.21 | All | All | All |
| Application | Webwizguide | Web Wiz Forums | 6.22 | All | All | All |
| Application | Webwizguide | Web Wiz Forums | 6.23 | All | All | All |
| Application | Webwizguide | Web Wiz Forums | 6.24 | All | All | All |
| Application | Webwizguide | Web Wiz Forums | 6.25 | All | All | All |
| Application | Webwizguide | Web Wiz Forums | 6.26 | All | All | All |
| Application | Webwizguide | Web Wiz Forums | 6.27 | All | All | All |
| Application | Webwizguide | Web Wiz Forums | 6.28 | All | All | All |
| Application | Webwizguide | Web Wiz Forums | 6.29 | All | All | All |
| Application | Webwizguide | Web Wiz Forums | 6.30 | All | All | All |
| Application | Webwizguide | Web Wiz Forums | 6.32 | All | All | All |
| Application | Webwizguide | Web Wiz Forums | 6.33 | All | All | All |
| Application | Webwizguide | Web Wiz Forums | 6.34 | All | All | All |
| Application | Webwizguide | Web Wiz Forums | 7 | beta_4 | All | All |
| Application | Webwizguide | Web Wiz Forums | 7 | rc1 | All | All |
| Application | Webwizguide | Web Wiz Forums | 7.0 | All | All | All |
| Application | Webwizguide | Web Wiz Forums | 7.01 | All | All | All |
| Application | Webwizguide | Web Wiz Forums | 7.5 | All | All | All |
| Application | Webwizguide | Web Wiz Forums | 7.5 | beta_1 | All | All |
| Application | Webwizguide | Web Wiz Forums | 7.51 | All | All | All |
| Application | Webwizguide | Web Wiz Forums | 7.51a | All | All | All |
| Application | Webwizguide | Web Wiz Forums | 7.6 | All | All | All |
| Application | Webwizguide | Web Wiz Forums | 7.7 | All | All | All |
| Application | Webwizguide | Web Wiz Forums | 7.7a | All | All | All |
| Application | Webwizguide | Web Wiz Forums | 7.8 | All | All | All |
| Application | Webwizguide | Web Wiz Forums | 7.9 | All | All | All |
| Application | Webwizguide | Web Wiz Forums | 7.92 | All | All | All |
| Application | Webwizguide | Web Wiz Forums | 7.95 | All | All | All |
| Application | Webwizguide | Web Wiz Forums | 7.96 | All | All | All |
| Application | Webwizguide | Web Wiz Forums | 8 | beta_1 | All | All |
| Application | Webwizguide | Web Wiz Forums | 8 | beta_2 | All | All |
| Application | Webwizguide | Web Wiz Forums | 8 | rc1 | All | All |
| Application | Webwizguide | Web Wiz Forums | 8 | rc1.1 | All | All |
| Application | Webwizguide | Web Wiz Forums | 8.0 | All | All | All |
| Application | Webwizguide | Web Wiz Forums | 8.01 | All | All | All |
| Application | Webwizguide | Web Wiz Forums | 8.02 | All | All | All |
| Application | Webwizguide | Web Wiz Forums | 8.03 | All | All | All |
| Application | Webwizguide | Web Wiz Forums | 8.04 | All | All | All |
| Application | Webwizguide | Web Wiz Forums | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityReason - Web Wiz Forums 8.05 (MySQL version) SQL Injection | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | Exploit |
| Ivan Fratric's Security Blog: Web Wiz Forums 8.05 (MySQL version) SQL Injection | af854a3a-2127-422b-91ae-364da2661108 | ifsec.blogspot.com | Exploit |
| Web Wiz Forums "formatSQLInput()" SQL Injection - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Web Wiz Forums - Free Bulletin Board System (BBS), Forum Software | af854a3a-2127-422b-91ae-364da2661108 | www.webwizguide.info | |
| Web Wiz Forums String Filtering SQL Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| osvdb.org/34344 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.