CVE-2007-0107

NameCVE-2007-0107
DescriptionWordPress before 2.0.6, when mbstring is enabled for PHP, decodes alternate character sets after escaping the SQL query, which allows remote attackers to bypass SQL injection protection schemes and execute arbitrary SQL commands via multibyte charsets, as demonstrated using UTF-7.
SourceCVE (at NVD; LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium (attack range: remote)
Debian Bugs405691

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
wordpress (PTS)wheezy (security), wheezy3.6.1+dfsg-1~deb7u10fixed
jessie (security), jessie4.1+dfsg-1+deb8u8fixed
stretch, sid4.5+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
wordpresssource(unstable)2.0.6-1medium405691

Notes

http://www.hardened-php.net/advisory_012007.140.html

Search for package or bug name: Reporting problems