Vulnerabilities > CVE-2006-3364 - SQL-Injection vulnerability in Blog Cms

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
f-art-agency
exploit available

Summary

SQL injection vulnerability in index.php in the NP_SEO plugin in BLOG:CMS before 4.1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. Upgrade to BLOG:CMS version 4.1.0 : http://sourceforge.net/project/showfiles.php?group_id=111880

Vulnerable Configurations

Part Description Count
Application
F-Art_Agency
1

Exploit-Db

descriptionBLOG:CMS <= 4.0.0k Remote SQL Injection Exploit. CVE-2006-3364. Webapps exploit for php platform
idEDB-ID:1960
last seen2016-01-31
modified2006-06-28
published2006-06-28
reporterrgod
sourcehttps://www.exploit-db.com/download/1960/
titleBLOG:CMS <= 4.0.0k Remote SQL Injection Exploit