PT-2007-1818 · Cvstrac · Cvstrac

Published

2007-01-29

·

Updated

2018-10-16

·

CVE-2007-0347

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: CVSTrac versions prior to 2.0.1
Description: The issue arises from the is eow function in format.c, which fails to properly check for the ' (quote) character. This allows remote authenticated users to execute limited SQL injection attacks, potentially causing a denial of service (database error) by including a ' character in certain messages, tickets, or Wiki entries.
Recommendations: For versions prior to 2.0.1, update to version 2.0.1 or later to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-0347

Affected Products

Cvstrac