Vulnerabilities > CVE-2006-0324 - Unspecified vulnerability in Webspot Webspotblogging 3.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN webspot
exploit available
Summary
SQL injection vulnerability in WebspotBlogging 3.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter to login.php.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | WebspotBlogging 3.0 Login.PHP SQL Injection Vulnerability. CVE-2006-0324. Webapps exploit for php platform |
id | EDB-ID:27114 |
last seen | 2016-02-03 |
modified | 2006-01-19 |
published | 2006-01-19 |
reporter | Aliaksandr Hartsuyeu |
source | https://www.exploit-db.com/download/27114/ |
title | WebspotBlogging 3.0 Login.PHP SQL Injection Vulnerability |
Seebug
bulletinFamily | exploit |
description | BUGTRAQ ID: 16319 CVE(CAN) ID: CVE-2006-0324 WebspotBlogging是一款PHP编写的Blog程序。 WebspotBlogging对用户提交给的参数缺少正确充分的过滤,远程攻击者可以利用此漏洞非授权操作数据库绕过认证。 WebspotBlogging的login.php脚本对用户提交username参数数据缺少充分过滤,远程攻击者可以通过在输入数据中插入特定的SQL命令来非授权获取对数据库的访问。 WebspotBlogging WebspotBlogging 3.0 WebspotBlogging --------------- 目前厂商还没有提供补丁或者升级程序,我们建议使用此软件的用户随时关注厂商的主页以获取最新版本: <a href=http://blogging.webspot.co.uk/ target=_blank>http://blogging.webspot.co.uk/</a> |
id | SSV:4232 |
last seen | 2017-11-19 |
modified | 2006-08-20 |
published | 2006-08-20 |
reporter | Root |
title | WebspotBlogging login.php远程SQL注入漏洞 |
References
- http://evuln.com/vulns/41/summary.html
- http://evuln.com/vulns/41/summary.html
- http://secunia.com/advisories/18560
- http://secunia.com/advisories/18560
- http://securityreason.com/securityalert/356
- http://securityreason.com/securityalert/356
- http://securitytracker.com/id?1015522
- http://securitytracker.com/id?1015522
- http://www.osvdb.org/22670
- http://www.osvdb.org/22670
- http://www.securityfocus.com/archive/1/422364/100/0/threaded
- http://www.securityfocus.com/archive/1/422364/100/0/threaded
- http://www.securityfocus.com/bid/16319
- http://www.securityfocus.com/bid/16319
- http://www.vupen.com/english/advisories/2006/0268
- http://www.vupen.com/english/advisories/2006/0268
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24222
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24222
- https://sourceforge.net/forum/forum.php?forum_id=532233
- https://sourceforge.net/forum/forum.php?forum_id=532233
- https://sourceforge.net/project/shownotes.php?release_id=387180&group_id=156586
- https://sourceforge.net/project/shownotes.php?release_id=387180&group_id=156586