CafeLog b2 Blog.Header Script SQL Injection Vulnerability
BID:7783
Info
CafeLog b2 Blog.Header Script SQL Injection Vulnerability
| Bugtraq ID: | 7783 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 02 2003 12:00AM |
| Updated: | Jun 02 2003 12:00AM |
| Credit: | Discovery credited to FraMe <[email protected]>. |
| Vulnerable: |
Cafelog b2 0.6.2 Cafelog b2 0.6.1 Cafelog b2 0.6 pre2 Cafelog b2 0.6 pre |
| Not Vulnerable: | |
Discussion
CafeLog b2 Blog.Header Script SQL Injection Vulnerability
The Cafelog b2 tool does not properly sanitize user input sent to the blog.header.php script. Because of this, it is possible for an attacker to pass malicious SQL code to the underlying database.
The Cafelog b2 tool does not properly sanitize user input sent to the blog.header.php script. Because of this, it is possible for an attacker to pass malicious SQL code to the underlying database.