We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2011-5110



Assignermitre
Reserved2012-08-23
Published2012-08-23
Updated2024-08-07

Description

Multiple SQL injection vulnerabilities in Blogs Manager 1.101 and earlier allow remote attackers to execute arbitrary SQL commands via the SearchField parameter in a search action to (1) _authors_list.php, (2) _blogs_list.php, (3) _category_list.php, (4) _comments_list.php, (5) _policy_list.php, (6) _rate_list.php, (7) categoriesblogs_list.php, (8) chosen_authors_list.php, (9) chosen_blogs_list.php, (10) chosen_comments_list.php, and (11) help_list.php in blogs/.

References

http://archives.neohapsis.com/archives/fulldisclosure/2011-11/0303.html (20111118 Blogs manager <= 1.101 SQL Injection Vulnerability) mailing-list

http://osvdb.org/77255 (77255) vdb-entry

http://osvdb.org/77256 (77256) vdb-entry

http://osvdb.org/77259 (77259) vdb-entry

http://osvdb.org/77251 (77251) vdb-entry

http://osvdb.org/77257 (77257) vdb-entry

http://osvdb.org/77258 (77258) vdb-entry

https://exchange.xforce.ibmcloud.com/vulnerabilities/71401 (blogsmanager-searchfield-sql-injection(71401)) vdb-entry

http://www.exploit-db.com/exploits/18129 (18129) exploit

http://sourceforge.net/tracker/?func=detail&aid=3506818&group_id=219284&atid=1045881

http://osvdb.org/77252 (77252) vdb-entry

http://osvdb.org/77260 (77260) vdb-entry

http://osvdb.org/77254 (77254) vdb-entry

http://www.securityfocus.com/archive/1/520571/100/0/threaded (20111119 Blogs manager <= 1.101 SQL Injection Vulnerability) mailing-list

http://www.securityfocus.com/bid/50731 (50731) vdb-entry

http://osvdb.org/77250 (77250) vdb-entry

http://osvdb.org/77253 (77253) vdb-entry

http://secunia.com/advisories/46918 (46918) third-party-advisory

cve.org CVE-2011-5110

nvd.nist.gov CVE-2011-5110

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2011-5110
Support options

Helpdesk Telegram

Subscribe to our newsletter to learn more about our work.