Vulnerabilities > CVE-2006-6191 - SQL-Injection vulnerability in 8Pixel.Net Simple Blog 2.0/2.1/2.2

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
8pixel-net
exploit available

Summary

SQL injection vulnerability in admin/edit.asp in 8pixel.net simpleblog 2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

Exploit-Db

descriptionSimpleBlog <= 2.3 (admin/edit.asp) Remote SQL Injection Vulnerability. CVE-2006-6191. Webapps exploit for asp platform
fileexploits/asp/webapps/2853.txt
idEDB-ID:2853
last seen2016-01-31
modified2006-11-26
platformasp
port
published2006-11-26
reporterbolivar
sourcehttps://www.exploit-db.com/download/2853/
titleSimpleBlog <= 2.3 admin/edit.asp Remote SQL Injection Vulnerability
typewebapps