Описание
Multiple SQL injection vulnerabilities in Simple Blog 2.1 allow remote attackers to execute arbitrary SQL commands via the month parameter in an archives view operation and possibly certain other parameters in unspecified scripts.
Ссылки
- ExploitVendor Advisory
- ExploitVendor Advisory
- Exploit
- Vendor Advisory
- ExploitVendor Advisory
- ExploitVendor Advisory
- Exploit
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.1 (включая)
cpe:2.3:a:8pixel.net:simple_blog:*:*:*:*:*:*:*:*
EPSS
Процентиль: 72%
0.00721
Низкий
7.5 High
CVSS2
Дефекты
CWE-89
Связанные уязвимости
github
почти 4 года назад
Multiple SQL injection vulnerabilities in Simple Blog 2.1 allow remote attackers to execute arbitrary SQL commands via the month parameter in an archives view operation and possibly certain other parameters in unspecified scripts.
EPSS
Процентиль: 72%
0.00721
Низкий
7.5 High
CVSS2
Дефекты
CWE-89