Topic : | Blog System v1.2 SQL injection
|
SecurityAlert : 6986
CVE : CVE-2010-0458
CWE : CWE-89
SecurityRisk : High (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : Yes
Credit : BorN To K!LL
Published : 31.01.2010
Affected Software : | netart_media:blog_system:1.5 |
 Advisory Content : Blog System v1.2 (http://www.netartmedia.net/blogsystem/)
is vulnerable to 2 SQL injection vulnerabilities for failure to correctly
sanitize SQL parameters.
http://[HOST]/index.php?mode=home&cat=-99[SQL CODE]
http://[HOST]/blog.php?user=[USER]¬e=-99[SQL CODE]
References :
http://xforce.iss.net/xforce/xfdb/55818
http://www.securityfocus.com/bid/37911
http://www.exploit-db.com/exploits/11216
http://packetstormsecurity.org/0512-exploits/blog12SQL.txt
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|