PT-2006-5611 · Clickblog · Clickblog

Ajann

·

Published

2006-09-19

·

Updated

2018-10-17

·

CVE-2006-4857

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ClickBlog version 2.0
Description The issue concerns a SQL injection vulnerability in the default.asp login page. This vulnerability allows remote attackers to execute arbitrary SQL commands by manipulating the username and form codeword (also known as the Password field) parameters in the login form.
Recommendations For ClickBlog version 2.0, consider restricting access to the default.asp login page until a fix is available, and avoid using the username and form codeword parameters in a way that could facilitate SQL injection attacks.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-4857

Affected Products

Clickblog