{"api_version":"1","generated_at":"2026-06-20T12:36:40+00:00","cve":"CVE-2007-0388","urls":{"html":"https://cve.report/CVE-2007-0388","api":"https://cve.report/api/cve/CVE-2007-0388.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-0388","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-0388"},"summary":{"title":"CVE-2007-0388","description":"SQL injection vulnerability in search.php in Woltlab Burning Board (wBB) 1.0.2 and earlier, and 2.3.6 and earlier in the 2.x series, allows remote attackers to execute arbitrary SQL commands via the boardids[1] and other boardids[] parameters.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-01-19 23:28:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://www.exploit-db.com/exploits/3144","name":"https://www.exploit-db.com/exploits/3144","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Woltlab Burning Board <= 1.0.2, 2.3.6 search.php SQL Injection Exploit 2","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31550","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31550","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/33872","name":"http://osvdb.org/33872","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.exploit-db.com/exploits/3143","name":"https://www.exploit-db.com/exploits/3143","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Woltlab Burning Board <= 1.0.2, 2.3.6 search.php SQL Injection Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-0388","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-0388","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"388","vulnerable":"1","versionEndIncluding":"1.0.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"woltlab","cpe5":"burning_board","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"388","vulnerable":"1","versionEndIncluding":"2.3.6","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"woltlab","cpe5":"burning_board","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T12:19:30.293Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"33872","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/33872"},{"name":"3143","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/3143"},{"name":"wbb-search-sql-injection(31550)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31550"},{"name":"3144","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/3144"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-01-17T00:00:00.000Z","descriptions":[{"lang":"en","value":"SQL injection vulnerability in search.php in Woltlab Burning Board (wBB) 1.0.2 and earlier, and 2.3.6 and earlier in the 2.x series, allows remote attackers to execute arbitrary SQL commands via the boardids[1] and other boardids[] parameters."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-10-18T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"33872","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/33872"},{"name":"3143","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/3143"},{"name":"wbb-search-sql-injection(31550)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31550"},{"name":"3144","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/3144"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-0388","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"SQL injection vulnerability in search.php in Woltlab Burning Board (wBB) 1.0.2 and earlier, and 2.3.6 and earlier in the 2.x series, allows remote attackers to execute arbitrary SQL commands via the boardids[1] and other boardids[] parameters."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"33872","refsource":"OSVDB","url":"http://osvdb.org/33872"},{"name":"3143","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/3143"},{"name":"wbb-search-sql-injection(31550)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31550"},{"name":"3144","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/3144"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-0388","datePublished":"2007-01-19T23:00:00.000Z","dateReserved":"2007-01-19T00:00:00.000Z","dateUpdated":"2024-08-07T12:19:30.293Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-01-19 23:28:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:woltlab:burning_board:*:*:*:*:*:*:*:*","versionEndIncluding":"1.0.2","matchCriteriaId":"E581F118-03FA-48A8-9C8D-FCD1DC1867E3"},{"vulnerable":true,"criteria":"cpe:2.3:a:woltlab:burning_board:*:*:*:*:*:*:*:*","versionEndIncluding":"2.3.6","matchCriteriaId":"22ADDCD6-DDEE-4E08-85BA-9E34DF5C92A6"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"388","Ordinal":"1","Title":"CVE-2007-0388","CVE":"CVE-2007-0388","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"388","Ordinal":"1","NoteData":"SQL injection vulnerability in search.php in Woltlab Burning Board (wBB) 1.0.2 and earlier, and 2.3.6 and earlier in the 2.x series, allows remote attackers to execute arbitrary SQL commands via the boardids[1] and other boardids[] parameters.","Type":"Description","Title":"CVE-2007-0388"},{"CveYear":"2007","CveId":"388","Ordinal":"2","NoteData":"2007-01-19","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"388","Ordinal":"3","NoteData":"2017-10-18","Type":"Other","Title":"Modified"}]}}}