BBlog RSS.PHP SQL Injection Vulnerability
BID:11303
Info
BBlog RSS.PHP SQL Injection Vulnerability
| Bugtraq ID: | 11303 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 01 2004 12:00AM |
| Updated: | Oct 01 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to James McGlinn <[email protected]>. |
| Vulnerable: |
bBlog bBlog 0.7.3 bBlog bBlog 0.7.2 |
| Not Vulnerable: | |
Discussion
BBlog RSS.PHP SQL Injection Vulnerability
It is reported that bBlog is prone to an SQL injection vulnerability. This issue is due to a failure of the application to properly validate user supplied URI input.
Because of this, a malicious user may influence database queries in order to view or modify sensitive information, potentially compromising the software or the database. It may be possible for an attacker to disclose the administrator password hash by exploiting this issue.
It is reported that bBlog is prone to an SQL injection vulnerability. This issue is due to a failure of the application to properly validate user supplied URI input.
Because of this, a malicious user may influence database queries in order to view or modify sensitive information, potentially compromising the software or the database. It may be possible for an attacker to disclose the administrator password hash by exploiting this issue.
Exploit / POC
BBlog RSS.PHP SQL Injection Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
BBlog RSS.PHP SQL Injection Vulnerability
Solution:
It is reported that the vendor has released version 0.3.4 to address this issue, this is not confirmed.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It is reported that the vendor has released version 0.3.4 to address this issue, this is not confirmed.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
BBlog RSS.PHP SQL Injection Vulnerability
References:
References:
- bBlog Homepage (bBlog)
- SQL Injection vulnerability in bBlog 0.7.3 (James McGlinn
)