PT-2006-1443 · Insane Visions · Insane Visions Blogphp

Imei

·

Published

2006-01-22

·

Updated

2018-10-19

·

CVE-2006-0372

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Insane Visions BlogPHP version 1.0
Description The issue concerns SQL injection vulnerabilities in the config.php file. Remote attackers can execute arbitrary SQL commands by manipulating the blogphp username or blogphp password parameter in a cookie.
Recommendations For Insane Visions BlogPHP version 1.0, consider restricting access to the config.php file and validating user input to prevent SQL injection attacks. As a temporary workaround, avoid using the blogphp username and blogphp password parameters in cookies until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-0372

Affected Products

Insane Visions Blogphp