CVE-2007-1962

Xoops Wf-snippets < 1.02 - SQL Injection

Title source: rule

Description

SQL injection vulnerability in index.php in the WF-Snippets 1.02 and earlier module for XOOPS allows remote attackers to execute arbitrary SQL commands via the c parameter in a cat action.

Exploits (1)

exploitdb WORKING POC VERIFIED
by ajann · htmlwebappsphp
https://www.exploit-db.com/exploits/3663

Scores

EPSS 0.0072
EPSS Percentile 72.5%

Details

CWE
CWE-89
Status published
Products (1)
xoops/wf-snippets < 1.02
Published Apr 11, 2007
Tracked Since Feb 18, 2026