PT-2006-1443 · Insane Visions · Insane Visions Blogphp
Imei
·
Published
2006-01-22
·
Updated
2018-10-19
·
CVE-2006-0372
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Insane Visions BlogPHP version 1.0
Description
The issue concerns SQL injection vulnerabilities in the config.php file. Remote attackers can execute arbitrary SQL commands by manipulating the
blogphp username or blogphp password parameter in a cookie.Recommendations
For Insane Visions BlogPHP version 1.0, consider restricting access to the config.php file and validating user input to prevent SQL injection attacks. As a temporary workaround, avoid using the
blogphp username and blogphp password parameters in cookies until a patch is available.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Insane Visions Blogphp