Vulnerability Description
Unspecified vulnerability in the fetch function in MDB2.php in PEAR Structures-DataGrid-DataSource-MDB2 0.1.9 and earlier allows attackers to "manipulate the generated sorting queries."
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pear | Structures Datagrid Datasource Mdb2 | <= 0.1.9 |
References
- http://osvdb.org/45805
- http://pear.php.net/package/Structures_DataGrid_DataSource_MDB2/download/0.1.10Patch
- http://www.vupen.com/english/advisories/2007/2425
- http://osvdb.org/45805
- http://pear.php.net/package/Structures_DataGrid_DataSource_MDB2/download/0.1.10Patch
- http://www.vupen.com/english/advisories/2007/2425
FAQ
What is CVE-2007-3628?
CVE-2007-3628 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Unspecified vulnerability in the fetch function in MDB2.php in PEAR Structures-DataGrid-DataSource-MDB2 0.1.9 and earlier allows attackers to "manipulate the generated sorting queries."
How severe is CVE-2007-3628?
CVE-2007-3628 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-3628?
Check the references section above for vendor advisories and patch information. Affected products include: Pear Structures Datagrid Datasource Mdb2.