Vulnerabilities > Mafia Moblog

DATE CVE VULNERABILITY TITLE RISK
2006-06-12 CVE-2006-2978 Remote Security vulnerability in Mafia Moblog
Mafia Moblog 0.6M1 and earlier allows remote attackers to obtain the installation path in an error message via a direct request to (1) big.php and (2) upgrade.php.
network
low complexity
mafia-moblog
5.0
2006-06-12 CVE-2006-2977 SQL Injection vulnerability in Mafia Moblog Mafia Moblog
SQL injection vulnerability in big.php in Mafia Moblog 0.6M1 and earlier allows remote attackers to execute arbitrary SQL commands via the img parameter.
network
low complexity
mafia-moblog CWE-89
7.5