PT-2005-3906 · Simplog · Simplog

Mustafa Can Bjorn Ipekci

+1

·

Published

2005-09-27

·

Updated

2008-09-05

·

CVE-2005-3076

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Simplog version 0.9.1
Description The issue allows remote attackers to execute arbitrary SQL commands or trigger SQL error messages. This can be achieved by providing invalid parameters to specific API endpoints, including pid, blogid, cid, or m parameters to "archive.php", or the blogid parameter to "blogadmin.php".
Recommendations For Simplog version 0.9.1, as a temporary workaround, consider validating and sanitizing the pid, blogid, cid, m, and blogid parameters in the "archive.php" and "blogadmin.php" files to prevent SQL injection attacks. Restrict access to these endpoints until a proper fix is applied. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-3076

Affected Products

Simplog