We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
Assigner | mitre |
Reserved | 2012-08-23 |
Published | 2012-08-23 |
Updated | 2024-08-07 |
Multiple SQL injection vulnerabilities in Blogs Manager 1.101 and earlier allow remote attackers to execute arbitrary SQL commands via the SearchField parameter in a search action to (1) _authors_list.php, (2) _blogs_list.php, (3) _category_list.php, (4) _comments_list.php, (5) _policy_list.php, (6) _rate_list.php, (7) categoriesblogs_list.php, (8) chosen_authors_list.php, (9) chosen_blogs_list.php, (10) chosen_comments_list.php, and (11) help_list.php in blogs/.
http://archives.neohapsis.com/archives/fulldisclosure/2011-11/0303.html (20111118 Blogs manager <= 1.101 SQL Injection Vulnerability)
http://osvdb.org/77255 (77255)
http://osvdb.org/77256 (77256)
http://osvdb.org/77259 (77259)
http://osvdb.org/77251 (77251)
http://osvdb.org/77257 (77257)
http://osvdb.org/77258 (77258)
https://exchange.xforce.ibmcloud.com/vulnerabilities/71401 (blogsmanager-searchfield-sql-injection(71401))
http://www.exploit-db.com/exploits/18129 (18129)
http://sourceforge.net/tracker/?func=detail&aid=3506818&group_id=219284&atid=1045881
http://osvdb.org/77252 (77252)
http://osvdb.org/77260 (77260)
http://osvdb.org/77254 (77254)
http://www.securityfocus.com/archive/1/520571/100/0/threaded (20111119 Blogs manager <= 1.101 SQL Injection Vulnerability)
http://www.securityfocus.com/bid/50731 (50731)
http://osvdb.org/77250 (77250)
http://osvdb.org/77253 (77253)
http://secunia.com/advisories/46918 (46918)