VYPR
Unrated severityNVD Advisory· Published Jan 29, 2007· Updated Apr 23, 2026

CVE-2007-0347

CVE-2007-0347

Description

The is_eow function in format.c in CVSTrac before 2.0.1 does not properly check for the "'" (quote) character, which allows remote authenticated users to execute limited SQL injection attacks and cause a denial of service (database error) via a ' character in certain messages, tickets, or Wiki entries.

Affected products

6
  • Cvstrac/Cvstrac6 versions
    cpe:2.3:a:cvstrac:cvstrac:*:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:cvstrac:cvstrac:*:*:*:*:*:*:*:*range: <=2.0
    • cpe:2.3:a:cvstrac:cvstrac:1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:cvstrac:cvstrac:1.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:cvstrac:cvstrac:1.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:cvstrac:cvstrac:1.1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:cvstrac:cvstrac:1.1.4:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

10

News mentions

0

No linked articles in our index yet.