BirdBlog AdminCore.PHP SQL Injection Vulnerability
BID:12880
Info
BirdBlog AdminCore.PHP SQL Injection Vulnerability
| Bugtraq ID: | 12880 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-0882 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 23 2005 12:00AM |
| Updated: | Jul 12 2009 11:56AM |
| Credit: | This vulnerability was announced by the vendor. |
| Vulnerable: |
BirdBlog BirdBlog 1.1 .0 BirdBlog BirdBlog 1.0 .0 |
| Not Vulnerable: |
BirdBlog BirdBlog 1.2 .0 |
Discussion
BirdBlog AdminCore.PHP SQL Injection Vulnerability
BirdBlog is affected by a remote SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in a SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
The vendor has addressed this issue in BirdBlog version 1.2.0.
BirdBlog is affected by a remote SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in a SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
The vendor has addressed this issue in BirdBlog version 1.2.0.
Exploit / POC
BirdBlog AdminCore.PHP SQL Injection Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
BirdBlog AdminCore.PHP SQL Injection Vulnerability
Solution:
The vendor has addressed this issue in BirdBlog version 1.2.0.
BirdBlog BirdBlog 1.0 .0
BirdBlog BirdBlog 1.1 .0
Solution:
The vendor has addressed this issue in BirdBlog version 1.2.0.
BirdBlog BirdBlog 1.0 .0
-
BirdBlog BirdBlog 1.2.0
http://birdblog.sourceforge.net/
BirdBlog BirdBlog 1.1 .0
-
BirdBlog BirdBlog 1.2.0
http://birdblog.sourceforge.net/
References
BirdBlog AdminCore.PHP SQL Injection Vulnerability
References:
References:
- BirdBlog Changelog (BirdBlog)
- BirdBlog Homepage (BirdBlog)