Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2007-0107
Description:WordPress before 2.0.6, when mbstring is enabled for PHP, decodes alternate character sets after escaping the SQL query, which allows remote attackers to bypass SQL injection protection schemes and execute arbitrary SQL commands via multibyte charsets, as demonstrated using UTF-7.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2007-0107
BugTraq ID: 21907
http://www.securityfocus.com/bid/21907
Bugtraq: 20070105 Advisory 02/2007: WordPress Trackback Charset Decoding SQL Injection Vulnerability (Google Search)
http://www.securityfocus.com/archive/1/456049/100/0/threaded
http://security.gentoo.org/glsa/glsa-200701-10.xml
http://www.hardened-php.net/advisory_022007.141.html
http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.005.html
http://osvdb.org/31579
http://secunia.com/advisories/23595
http://secunia.com/advisories/23741
http://securityreason.com/securityalert/2112
http://www.vupen.com/english/advisories/2007/0061
XForce ISS Database: wordpress-mbstring-security-bypass(31297)
https://exchange.xforce.ibmcloud.com/vulnerabilities/31297




© 1998-2025 E-Soft Inc. All rights reserved.