Vulnerability Description
SQL injection vulnerability in bb-includes/formatting-functions.php in bbPress before 0.8.1 might allow remote attackers to execute arbitrary SQL commands via unspecified vectors to forums/bb-edit.php, as demonstrated by a PRE element, aka the "quircky slashes bug."
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bbpress | Bbpress | 0.8 |
References
- http://bbpress.org/blog/2007/02/bbpress-081/Patch
- http://osvdb.org/36606
- http://secunia.com/advisories/25696
- http://trac.bbpress.org/changeset/717
- http://trac.bbpress.org/ticket/592
- http://www.securityfocus.com/bid/24488
- http://www.vupen.com/english/advisories/2007/2219
- http://bbpress.org/blog/2007/02/bbpress-081/Patch
- http://osvdb.org/36606
- http://secunia.com/advisories/25696
- http://trac.bbpress.org/changeset/717
- http://trac.bbpress.org/ticket/592
- http://www.securityfocus.com/bid/24488
- http://www.vupen.com/english/advisories/2007/2219
FAQ
What is CVE-2007-3244?
CVE-2007-3244 is a vulnerability with a CVSS score of 7.5 (HIGH). SQL injection vulnerability in bb-includes/formatting-functions.php in bbPress before 0.8.1 might allow remote attackers to execute arbitrary SQL commands via unspecified vectors to forums/bb-edit.php...
How severe is CVE-2007-3244?
CVE-2007-3244 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-3244?
Check the references section above for vendor advisories and patch information. Affected products include: Bbpress Bbpress.