CafeLog b2 WebLog Tool SQL Injection Vulnerability
BID:5456
Info
CafeLog b2 WebLog Tool SQL Injection Vulnerability
| Bugtraq ID: | 5456 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-1465 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 13 2002 12:00AM |
| Updated: | Jul 11 2009 03:56PM |
| Credit: | Reported by "Matthew Murphy" <[email protected]>. |
| Vulnerable: |
Cafelog b2 2.6 pre4 |
| Not Vulnerable: | |
Discussion
CafeLog b2 WebLog Tool SQL Injection Vulnerability
CafeLog b2 WebLog Tool allows users to generate news pages and weblogs dynamically. It uses PHP and a MySQL database to generate dynamic pages.
The b2 WebLog Tool does not properly sanitize data that is sent to the tableposts variable. This could allow an attacker to modify the logic of SQL queries, allowing for execution of commands on the database.
CafeLog b2 WebLog Tool allows users to generate news pages and weblogs dynamically. It uses PHP and a MySQL database to generate dynamic pages.
The b2 WebLog Tool does not properly sanitize data that is sent to the tableposts variable. This could allow an attacker to modify the logic of SQL queries, allowing for execution of commands on the database.
Exploit / POC
CafeLog b2 WebLog Tool SQL Injection Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
CafeLog b2 WebLog Tool SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.