← All CVEs

CVE-2007-0107

medium · 6.8

WordPress before 2.0.6, when mbstring is enabled for PHP, decodes alternate character sets after escaping the SQL query, which allows remote attackers to bypass SQL injection protection schemes and execute arbitrary SQL commands via multibyte charsets, as demonstrated using UTF-7.

6.8
CVSS
11.4%
EPSS (exploit prob.)
96th
EPSS percentile
2007-01-09
Published

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

VendorProductAffected versions
wordpresswordpress<= 2.0.5

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-0107