Vulnerabilities > CVE-2007-3889 - SQL-Injection vulnerability in Insanely Simple Blog

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
insanely-simple-blog
exploit available

Summary

Multiple SQL injection vulnerabilities in Insanely Simple Blog 0.5 and earlier allow remote attackers to execute arbitrary SQL commands via the current_subsection parameter to index.php and other unspecified vectors.

Vulnerable Configurations

Part Description Count
Application
Insanely_Simple_Blog
1

Exploit-Db

  • descriptionInsanely Simple Blog 0.4/0.5 index.php current_subsection Parameter SQL Injection. CVE-2007-3889 . Webapps exploit for php platform
    idEDB-ID:30317
    last seen2016-02-03
    modified2007-07-17
    published2007-07-17
    reporterjoseph.giron13
    sourcehttps://www.exploit-db.com/download/30317/
    titleInsanely Simple Blog 0.4/0.5 index.php current_subsection Parameter SQL Injection
  • idEDB-ID:5774