Vulnerabilities > CVE-2007-4055 - SQL Injection vulnerability in 8Pixel.Net Simple Blog 3.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
8pixel-net
exploit available

Summary

SQL injection vulnerability in comments_get.asp in SimpleBlog 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: this may be related to CVE-2006-4300.

Vulnerable Configurations

Part Description Count
Application
8Pixel.Net
1

Exploit-Db

descriptionSimpleBlog 3.0 (comments_get.asp id) Remote SQL Injection Vulnerability. CVE-2007-4055. Webapps exploit for asp platform
fileexploits/asp/webapps/4239.txt
idEDB-ID:4239
last seen2016-01-31
modified2007-07-28
platformasp
port
published2007-07-28
reporterg00ns
sourcehttps://www.exploit-db.com/download/4239/
titleSimpleBlog 3.0 comments_get.asp id Remote SQL Injection Vulnerability
typewebapps