← Vulnerability feed

Vulnerability record · CVE-2007-1607 · published 22 March 2007

CVE-2007-1607: W-agora vulnerability

W Agora · W Agora

search.php in w-Agora (Web-Agora) allows remote attackers to obtain potentially sensitive information via a ' (quote) value followed by certain SQL sequences in the (1) search_forum or (2) search_user parameter, which force a SQL error.

5.0 CVSS 2.0 Medium EPSS 2.3% · top 17.1%
5.0CVSS 2.0 base score
2.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

search.php in w-Agora (Web-Agora) allows remote attackers to obtain potentially sensitive information via a ' (quote) value followed by certain SQL sequences in the (1) search_forum or (2) search_user parameter, which force a SQL error.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-1607 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2010-4867W-agora path traversal vulnerabilityDirectory traversal vulnerability in search.php3 (aka search.php) in W-Agora 4.2.1 and earlier allows remote attackers to include and execute arbitra…EPSS 2.4%7.5CVE-2008-1466W-agora code injection vulnerabilityMultiple PHP remote file inclusion vulnerabilities in W-Agora 4.0 allow remote attackers to execute arbitrary PHP code via a URL in the bn_dir_defaul…EPSS 2.2%7.5CVE-2007-6647W-agora sql injection vulnerabilitySQL injection vulnerability in index.php in w-Agora 4.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter.EPSS 1.0%7.5CVE-2007-1604W-agora vulnerabilityMultiple unrestricted file upload vulnerabilities in w-Agora (Web-Agora) allow remote attackers to upload and execute arbitrary PHP code (1) via a fo…EPSS 3.0%7.5CVE-2004-1562W-agora vulnerabilitySQL injection vulnerability in redir_url.php in w-Agora 4.1.6a allows remote attackers to execute arbitrary SQL commands via the key parameter.EPSS 1.4%5.0CVE-2007-1605W-agora vulnerabilityw-Agora (Web-Agora) allows remote attackers to obtain sensitive information via a request to rss.php with an invalid (1) site or (2) bn parameter, (3…EPSS 1.7%5.0CVE-2007-0606W-agora vulnerabilityw-agora 4.2.1 allows remote attackers to obtain sensitive information by via the (1) bn[] array parameter to index.php, which expects a string, and (…EPSS 1.6%5.0CVE-2005-2648W-agora vulnerabilityDirectory traversal vulnerability in index.php in W-Agora 4.2.0 and earlier allows remote attackers to read arbitrary files via the site parameter.EPSS 3.6%

Source: NIST National Vulnerability Database (record CVE-2007-1607), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.