Vulnerabilities > CVE-2007-3974 - Input Validation vulnerability in Jblog 1.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
jblog
exploit available

Summary

admin/ajoutaut.php in JBlog 1.0 does not require authentication, which allows remote attackers to create arbitrary accounts via modified mot and droit parameters.

Vulnerable Configurations

Part Description Count
Application
Jblog
1

Exploit-Db

  • descriptionJBlog 1.0 (index.php id) Remote SQL Injection Exploit. CVE-2007-3973,CVE-2007-3974,CVE-2007-4919. Webapps exploit for php platform
    fileexploits/php/webapps/4408.pl
    idEDB-ID:4408
    last seen2016-01-31
    modified2007-09-14
    platformphp
    port
    published2007-09-14
    reporters4mi
    sourcehttps://www.exploit-db.com/download/4408/
    titleJBlog 1.0 index.php id Remote SQL Injection Exploit
    typewebapps
  • descriptionJBlog 1.0 Create / Delete Admin Authentication Bypass Exploit. CVE-2007-3973,CVE-2007-3974,CVE-2007-4919. Webapps exploit for php platform
    fileexploits/php/webapps/4211.html
    idEDB-ID:4211
    last seen2016-01-31
    modified2007-07-21
    platformphp
    port
    published2007-07-21
    reporters4mi
    sourcehttps://www.exploit-db.com/download/4211/
    titleJBlog 1.0 Create / Delete Admin Authentication Bypass Exploit
    typewebapps