7.5
CVSSv2

CVE-2006-5976

Published: 20/11/2006 Updated: 17/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in admin_login.asp in BlogMe 3.0 allow remote malicious users to execute arbitrary SQL commands via the (1) Username or (2) Password field. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

drumster blogme 3.0

Exploits

blogme v3 [admin login bypass & xss (post)] vendor site:wwwdrumsternet/ product:blogme v3 bug:login bypass & xss (post) risk:high admin login bypass : user : ' or '1' = '1 passwd: 1'='1' ro ' xss post : in: /commentsasp?blog=85 vulnerables fields: - Name - URL - Comments laurent gaffié & benjamin mossé s-a-p ...