NVD

Id
52574  
Name
CVE-2007-0347  
Description
The is_eow function in format.c in CVSTrac before 2.0.1 does not properly check for the """ (quote) character, which allows remote authenticated users to execute limited SQL injection attacks and cause a denial of service (database error) via a " character in certain messages, tickets, or Wiki entries.  
Reject
 
CVSS Version
2  
CVSS Score
4.3  
Severity
Medium  
CVSS Base Score
4.3  
CVSS Impact Subscore
2.9  
CVSS Exploit Subscore
8.6  
CVSS Vector
(AV:N/AC:M/Au:N/C:N/I:N/A:P)  
Pub Date
2017-01-07  
Published
2007-01-29  
Modified Date
2011-03-07  
Seq
2007-0347  

Actions