PT-2007-7352 · Woltlab · Woltlab Burning Board (Wbb) Lite

Published

2007-12-24

·

Updated

2018-10-15

·

CVE-2007-6518

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions WoltLab Burning Board (wBB) Lite version 1.0.2 pl3e
Description The issue concerns multiple SQL injection vulnerabilities in the search.php file. These vulnerabilities allow remote attackers to execute arbitrary SQL commands by manipulating specific parameters. The vulnerable parameters are showposts, sortby, and sortorder.
Recommendations For WoltLab Burning Board (wBB) Lite version 1.0.2 pl3e, consider restricting access to the search.php file until a patch is available. As a temporary workaround, avoid using the showposts, sortby, and sortorder parameters in the search functionality to minimize the risk of exploitation.

Exploit

Fix

RCE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-6518

Affected Products

Woltlab Burning Board (Wbb) Lite