CVE-2007-1974

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/04/2007
Last modified:
09/04/2025

Description

SQL injection vulnerability in the getArticle function in class/wfsarticle.php in WF-Section (aka WF-Sections) 1.0.1, as used in Xoops modules such as (1) Zmagazine 1.0, (2) Happy Linux XFsection 1.07 and earlier, and possibly other modules, allows remote attackers to execute arbitrary SQL commands via the articleid parameter to print.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wf-sections:wf-sections:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:xoops:happy_linux_xfsection_module:*:*:*:*:*:*:*:* 1.07 (including)
cpe:2.3:a:xoops:zmagazine_module:1.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools