CVE-2008-0360 Information

Description

Multiple SQL injection vulnerabilities in BLOG:CMS 4.2.1b allow remote attackers to execute arbitrary SQL commands via (1) the blogid parameter to index.php (2) the user parameter to action.php or (3) the field parameter to admin/plugins/table/index.php.

Reference

http://blogcms.com/wiki/changelog http://marc.info/?l=bugtraq&m=120049816924383&w=2 http://secunia.com/advisories/28523 http://www.securityfocus.com/bid/27317 https://www.exploit-db.com/exploits/4919

Share on: