PT-2006-1385 · Aoblogger · Aoblogger

Aliaksandr Hartsuyeu

·

Published

2006-01-19

·

Updated

2024-02-14

·

CVE-2006-0312

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions aoblogger version 2.3
Description The issue allows remote attackers to bypass authentication and create new blog entries. This is achieved by setting the uza parameter to 1 in the create.php file.
Recommendations For aoblogger version 2.3, consider restricting access to the create.php file until a patch is available, or avoid using the uza parameter to minimize the risk of exploitation.

Exploit

Fix

Related Identifiers

CVE-2006-0312

Affected Products

Aoblogger