BlognPlus Unspecified SQL Injection Vulnerability
BID:29764
Info
BlognPlus Unspecified SQL Injection Vulnerability
| Bugtraq ID: | 29764 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-2819 |
| Remote: | Yes |
| Local: | No |
| Published: | May 28 2008 12:00AM |
| Updated: | May 07 2015 05:28PM |
| Credit: | Mr. Hideyuki Naitou |
| Vulnerable: |
Blogn BlognPlus 2.5.4 |
| Not Vulnerable: |
Blogn BlognPlus 2.5.5 |
Discussion
BlognPlus Unspecified SQL Injection Vulnerability
BlognPlus is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The issue affects BlognPlus 2.5.4 and prior versions for MySQL and PostgreSQL editions.
BlognPlus is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The issue affects BlognPlus 2.5.4 and prior versions for MySQL and PostgreSQL editions.
Exploit / POC
BlognPlus Unspecified SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
BlognPlus Unspecified SQL Injection Vulnerability
Solution:
The vendor has released updates. Please see the references for more information.
Solution:
The vendor has released updates. Please see the references for more information.
References
BlognPlus Unspecified SQL Injection Vulnerability
References:
References:
- BlognPlus Homepage (BlognPlus)
- BlognPlus SQL Injection Vulnerability (BlognPlus)
- JVN#14072646 (JVN)