CVE-2007-3204

Publication date 12 June 2007

Last updated 17 July 2025


Ubuntu priority

Description

SQL injection vulnerability in auth.php in Just For Fun Network Management System (JFFNMS) 0.8.4-pre2 allows remote attackers to execute arbitrary SQL commands via the pass parameter. NOTE: this issue reportedly exists because of an initial incomplete fix for CVE-2007-3190. The provenance of this information is unknown; the details are obtained solely from third party information.

Read the notes from the security team

Status

Package Ubuntu Release Status
jffnms 7.10 gutsy
Not affected
7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper
Not affected

Notes


fujitsu

The fix for CVE-2007-3192 appears to have fixed this.


Access our resources on patching vulnerabilities