CVE-2007-1974
Summary
| CVE | CVE-2007-1974 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-04-12 00:19:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | SQL injection vulnerability in the getArticle function in class/wfsarticle.php in WF-Section (aka WF-Sections) 1.0.1, as used in Xoops modules such as (1) Zmagazine 1.0, (2) Happy Linux XFsection 1.07 and earlier, and possibly other modules, allows remote attackers to execute arbitrary SQL commands via the articleid parameter to print.php. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Wf-sections | Wf-sections | 1.0.1 | All | All | All |
| Application | Xoops | Happy Linux Xfsection Module | All | All | All | All |
| Application | Xoops | Zmagazine Module | 1.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| XOOPS Project - WF-Sections V2.08 Released (PHP5 Update) [Support Forums - Module usage questions] | af854a3a-2127-422b-91ae-364da2661108 | www.xoops.org | Vendor Advisory |
| osvdb.org/41387 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| XOOPS Project - WF-Sections 1.02 (Security BugFix) - Modules - XOOPS News | af854a3a-2127-422b-91ae-364da2661108 | www.xoops.org | Patch, Vendor Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| XOOPS Module ZMagazine Print.PHP SQL Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| XOOPS Module Zmagazine 1.0 - 'print.php' SQL Injection - PHP webapps Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| XFSection Xoops Module Print.PHP SQL Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| addons.zarilia.com/index.php | af854a3a-2127-422b-91ae-364da2661108 | addons.zarilia.com | Patch |
| XOOPS Module WF-Section <= 1.01 (articleid) SQL Injection Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| [VIM] WF-Sections SQL injection vendor ack; shows up in other modules | af854a3a-2127-422b-91ae-364da2661108 | www.attrition.org | Vendor Advisory |
| XOOPS WF-Section Module Print.PHP SQL Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| XOOPS Module XFsection 1.07 - 'articleId' Blind SQL Injection - PHP webapps Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| osvdb.org/52230 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.