CVE Database
/

CVE-2011-5110

Back to search

CVE-2011-5110

Published: Aug 23, 2012

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple SQL injection vulnerabilities in Blogs Manager 1.101 and earlier allow remote attackers to execute arbitrary SQL commands via the SearchField parameter in a search action to (1) _authors_list.php, (2) _blogs_list.php, (3) _category_list.php, (4) _comments_list.php, (5) _policy_list.php, (6) _rate_list.php, (7) categoriesblogs_list.php, (8) chosen_authors_list.php, (9) chosen_blogs_list.php, (10) chosen_comments_list.php, and (11) help_list.php in blogs/.

VendorProductVersions

n/a

n/a

affected
n/a

References

77255
vdb-entry
x_refsource_OSVDB
77256
vdb-entry
x_refsource_OSVDB
77259
vdb-entry
x_refsource_OSVDB
77251
vdb-entry
x_refsource_OSVDB
77257
vdb-entry
x_refsource_OSVDB
77258
vdb-entry
x_refsource_OSVDB
18129
exploit
x_refsource_EXPLOIT-DB
77252
vdb-entry
x_refsource_OSVDB
77260
vdb-entry
x_refsource_OSVDB
77254
vdb-entry
x_refsource_OSVDB
50731
vdb-entry
x_refsource_BID
77250
vdb-entry
x_refsource_OSVDB
77253
vdb-entry
x_refsource_OSVDB
46918
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now