PT-2005-4913 · Mybloggie · Mybloggie
Publicado
2005-12-14
·
Atualizado
2018-10-19
·
CVE-2005-4225
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
myBloggie version 2.1.3 beta
Description
The issue allows remote attackers to execute arbitrary SQL commands via multiple parameters in various PHP files, including
category in "add.php", cat desc in "addcat.php", level and user in "adduser.php", post id in "del.php", cat id in "delcat.php", comment id in "delcomment.php", id in "deluser.php", post id and category in "edit.php", cat id and cat desc in "editcat.php", and id, level, and user in "edituser.php".Recommendations
For myBloggie version 2.1.3 beta, consider temporarily restricting access to the vulnerable parameters, such as
category, cat desc, level, user, post id, cat id, comment id, and id, in the respective PHP files until a patch is available. Avoid using these parameters in the affected API endpoints until the issue is resolved.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Mybloggie