CVE-2005-1500
CVE-2005-1500
Multiple SQL injection vulnerabilities in myBloggie 2.1.1 allow remote attackers to execute arbitrary SQL commands via (1) the keyword parameter in search.php; or (2) the date_no parameter in viewdate mode, (3) the cat_id parameter in viewcat mode, the (4) month_no or (5) year parameter in viewmonth mode, or (6) post_id parameter in viewid mode to index.php. NOTE: item (1) was discovered to affect 2.1.3 as well.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/1023unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://marc.info/?l=bugtraq&m=111531904608224&w=2http://marc.info/?l=bugtraq&m=111722848308367&w=2http://mywebland.com/forums/viewtopic.php?t=180http://secunia.com/advisories/14980https://exchange.xforce.ibmcloud.com/vulnerabilities/20439http://www.securityfocus.com/bid/13507http://www.securityfocus.com/bid/15017