NVD

Id
53732  
Name
CVE-2007-1548  
Description
SQL injection vulnerability in functions/functions_filters.asp in Web Wiz Forums before 8.05a (MySQL version) does not properly filter certain characters in SQL commands, which allows remote attackers to execute arbitrary SQL commands via "" (backslash double-quote quote) sequences, which are collapsed into "", as demonstrated via the name parameter to forum/pop_up_member_search.asp.  
Reject
 
CVSS Version
2  
CVSS Score
7.5  
Severity
High  
CVSS Base Score
7.5  
CVSS Impact Subscore
6.4  
CVSS Exploit Subscore
10  
CVSS Vector
(AV:N/AC:L/Au:N/C:P/I:P/A:P)  
Pub Date
2017-01-07  
Published
2007-03-20  
Modified Date
2011-03-07  
Seq
2007-1548  

Actions