PT-2008-1424 · Mybloggie · Mybloggie

Jesper Jurcenoks

·

Publicado

2008-07-09

·

Atualizado

2017-10-11

·

CVE-2007-1899

CVSS v2.0

5.1

Média

VetorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions myBloggie version 2.1.6
Description The issue allows remote attackers to execute arbitrary SQL commands via the user id parameter in a "viewuser" action to "index.php", and also allows remote authenticated administrators to execute arbitrary SQL commands via the post id parameter in an "edit" action to "admin.php".
Recommendations For myBloggie version 2.1.6, update to a version that fixes the SQL injection vulnerabilities. As a temporary workaround, consider restricting access to the "viewuser" action in "index.php" and the "edit" action in "admin.php" to minimize the risk of exploitation. Avoid using the user id and post id parameters in the affected API endpoints until the issue is resolved.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-1899

Produtos afetados

Mybloggie