Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2007-6318SQL Injection in Wordpress

CWE-89SQL Injection7 documents7 sources
Severity
6.8MEDIUMNVD
EPSS
3.5%
top 12.31%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedDec 12
Latest updateMay 1

Description

SQL injection vulnerability in wp-includes/query.php in WordPress 2.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the s parameter, when DB_CHARSET is set to (1) Big5, (2) GBK, or possibly other character set encodings that support a "\" in a multibyte character.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages3 packages

debiandebian/wordpress< wordpress 2.3.2-1 (bookworm)
Debianwordpress/wordpress< 2.3.2-1+3
NVDwordpress/wordpress24 versions+23

🔴Vulnerability Details

2
GHSA
GHSA-79q4-xv4r-946x: SQL injection vulnerability in wp-includes/query2022-05-01
OSV
CVE-2007-6318: SQL injection vulnerability in wp-includes/query2007-12-12

💥Exploits & PoCs

1
Exploit-DB
WordPress Core 2.3.1 - Charset SQL Injection2007-12-11

📋Vendor Advisories

2
Red Hat
wordpress: SQL injection when certain DB charsets are used2007-12-10
Debian
CVE-2007-6318: wordpress - SQL injection vulnerability in wp-includes/query.php in WordPress 2.3.1 and earl...2007

💬Community

1
Bugzilla
CVE-2007-6318 wordpress: SQL injection when certain DB charsets are used2007-12-12
CVE-2007-6318 — SQL Injection in Debian Wordpress | cvebase