Wsn · Wsn Guest · CVE-2007-1517
**Name of the Vulnerable Software and Affected Versions**
WSN Guest versions 1.02 through 1.21
**Description**
A SQL injection issue allows remote attackers to execute arbitrary SQL commands via the `id` parameter in the comments.php file.
**Recommendations**
For WSN Guest versions 1.02 through 1.21, avoid using the `id` parameter in the comments.php file until a fix is available. As a temporary workaround, consider restricting access to the comments.php file to minimize the risk of exploitation.