CVE-2008-2670 Information

Description

Multiple SQL injection vulnerabilities in index.php in Insanely Simple Blog 0.5 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter or (2) the term parameter in a search action. NOTE: the current_subsection parameter is already covered by CVE-2007-3889.

Reference

http://chroot.org/exploits/chroot_uu_010 http://securityreason.com/securityalert/3938 http://www.securityfocus.com/archive/1/493224/100/0/threaded http://www.securityfocus.com/bid/29630 https://www.exploit-db.com/exploits/5774

Share on: