SmartBlog Multiple Input Validation Vulnerabilities
BID:29043
Info
SmartBlog Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 29043 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-2185 CVE-2008-2184 |
| Remote: | Yes |
| Local: | No |
| Published: | May 05 2008 12:00AM |
| Updated: | Jul 06 2016 02:17PM |
| Credit: | These vulnerabilities were discovered by anonymous researchers. |
| Vulnerable: |
SmartBlog SmartBlog 1.3 |
| Not Vulnerable: | |
Discussion
SmartBlog Multiple Input Validation Vulnerabilities
SmartBlog is prone to multiple vulnerabilities, including SQL-injection issues and a local file-include issue, because it fails to sufficiently sanitize user-supplied data.
Successful exploits of these vulnerabilities may allow attackers to compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, or view files and execute local scripts in the context of the webserver process.
SmartBlog 1.3 is vulnerable; other versions may also be affected.
SmartBlog is prone to multiple vulnerabilities, including SQL-injection issues and a local file-include issue, because it fails to sufficiently sanitize user-supplied data.
Successful exploits of these vulnerabilities may allow attackers to compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, or view files and execute local scripts in the context of the webserver process.
SmartBlog 1.3 is vulnerable; other versions may also be affected.
Exploit / POC
SmartBlog Multiple Input Validation Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
SmartBlog Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].