CVE Database
/

CVE-2005-3153

Back to search

CVE-2005-3153

Published: Oct 5, 2005

Modified: Aug 7, 2024

PUBLISHED

Description

login.php in myBloggie 2.1.3 beta and earlier allows remote attackers to bypass a whitelist regular expression and conduct SQL injection attacks via a username parameter with SQL after a null character, which causes the whitelist check to succeed but injects the SQL into a query string, a different vulnerability than CVE-2005-2838. NOTE: it is possible that this is actually a bug in PHP code, in which case this should not be treated as a myBloggie vulnerability.

VendorProductVersions

n/a

n/a

affected
n/a

References

1014995
vdb-entry
x_refsource_SECTRACK
42
third-party-advisory
x_refsource_SREASON
19935
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now