Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2007-0107SQL Injection in Wordpress

6 documents6 sources
Severity
6.8MEDIUMNVD
EPSS
6.9%
top 8.55%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJan 9
Latest updateMay 1

Description

WordPress before 2.0.6, when mbstring is enabled for PHP, decodes alternate character sets after escaping the SQL query, which allows remote attackers to bypass SQL injection protection schemes and execute arbitrary SQL commands via multibyte charsets, as demonstrated using UTF-7.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages3 packages

debiandebian/wordpress< wordpress 2.0.6-1 (bookworm)
Debianwordpress/wordpress< 2.0.6-1+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-mm56-chx8-v576: WordPress before 22022-05-01
OSV
CVE-2007-0107: WordPress before 22007-01-09

💥Exploits & PoCs

1
Exploit-DB
WordPress Core 2.0.5 - Trackback UTF-7 SQL Injection2007-01-07

📋Vendor Advisories

1
Debian
CVE-2007-0107: wordpress - WordPress before 2.0.6, when mbstring is enabled for PHP, decodes alternate char...2007

💬Community

1
Bugzilla
CVE-2007-0{106,107,109,262}: Wordpress < 2.0.7 multiple vulnerabilities2007-01-17
CVE-2007-0107 — SQL Injection in Debian Wordpress | cvebase