Vulnerabilities > CVE-2007-3244 - Unspecified vulnerability in Bbpress 0.8
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
SQL injection vulnerability in bb-includes/formatting-functions.php in bbPress before 0.8.1 might allow remote attackers to execute arbitrary SQL commands via unspecified vectors to forums/bb-edit.php, as demonstrated by a PRE element, aka the "quircky slashes bug."
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- http://bbpress.org/blog/2007/02/bbpress-081/
- http://bbpress.org/blog/2007/02/bbpress-081/
- http://osvdb.org/36606
- http://osvdb.org/36606
- http://secunia.com/advisories/25696
- http://secunia.com/advisories/25696
- http://trac.bbpress.org/changeset/717
- http://trac.bbpress.org/changeset/717
- http://trac.bbpress.org/ticket/592
- http://trac.bbpress.org/ticket/592
- http://www.securityfocus.com/bid/24488
- http://www.securityfocus.com/bid/24488
- http://www.vupen.com/english/advisories/2007/2219
- http://www.vupen.com/english/advisories/2007/2219