CVE Vulnerabilities

CVE-2007-0107

Published: Jan 09, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

WordPress before 2.0.6, when mbstring is enabled for PHP, decodes alternate character sets after escaping the SQL query, which allows remote attackers to bypass SQL injection protection schemes and execute arbitrary SQL commands via multibyte charsets, as demonstrated using UTF-7.

Affected Software

NameVendorStart VersionEnd Version
WordpressWordpress*2.0.5 (including)
WordpressUbuntudapper*
WordpressUbuntuedgy*
WordpressUbuntuupstream*

References