PT-2006-1315 · Unknown · Simple Blog

Published

2006-01-18

·

Updated

2017-07-20

·

CVE-2006-0240

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Simple Blog version 2.1
Description The issue allows remote attackers to execute arbitrary SQL commands, potentially via the month parameter in an archives view operation and possibly certain other parameters in unspecified scripts.
Recommendations For Simple Blog version 2.1, consider restricting access to the archives view operation and unspecified scripts that may be vulnerable to SQL injection until a patch is available. As a temporary workaround, avoid using the month parameter in the archives view operation to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-0240

Affected Products

Simple Blog