PT-2006-1385 · Aoblogger · Aoblogger

·

CVE-2006-0312

·

Published

2006-01-19

·

Updated

2024-02-14

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions aoblogger version 2.3
Description The issue allows remote attackers to bypass authentication and create new blog entries. This is achieved by setting the uza parameter to 1 in the create.php file.
Recommendations For aoblogger version 2.3, consider restricting access to the create.php file until a patch is available, or avoid using the uza parameter to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-0312

Affected Products

Aoblogger