Vulnerability CVE-2007-4919


Published: 2007-09-17   Modified: 2012-02-12

Description:
Multiple SQL injection vulnerabilities in JBlog 1.0 allow (1) remote attackers to execute arbitrary SQL commands via the id parameter to index.php, and allow (2) remote authenticated administrators to execute arbitrary SQL commands via the id parameter to admin/modifpost.php.

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Jblog -> Jblog 

 References:
http://www.securityfocus.com/bid/25669
http://www.vupen.com/english/advisories/2007/3178
https://exchange.xforce.ibmcloud.com/vulnerabilities/36602
https://www.exploit-db.com/exploits/4408

Copyright 2024, cxsecurity.com

 

Back to Top