Back to search
CVE-2005-1500
Published: May 11, 2005
Modified: Aug 7, 2024
PUBLISHED
Description
Multiple SQL injection vulnerabilities in myBloggie 2.1.1 allow remote attackers to execute arbitrary SQL commands via (1) the keyword parameter in search.php; or (2) the date_no parameter in viewdate mode, (3) the cat_id parameter in viewcat mode, the (4) month_no or (5) year parameter in viewmonth mode, or (6) post_id parameter in viewid mode to index.php. NOTE: item (1) was discovered to affect 2.1.3 as well.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://mywebland.com/forums/viewtopic.php?t=180
x_refsource_MISC
20050505 Multiple vulnerabilities in myBloggie 2.1.1
mailing-list
x_refsource_BUGTRAQ
20050527 SQL Injection Exploit for myBloggie 2.1.1 - 2.1.2
mailing-list
x_refsource_BUGTRAQ
14980
third-party-advisory
x_refsource_SECUNIA
13507
vdb-entry
x_refsource_BID
mybloggie-sql-injection(20439)
vdb-entry
x_refsource_XF
15017
vdb-entry
x_refsource_BID
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now