7.5
CVSSv2

CVE-2007-3003

Published: 04/06/2007 Updated: 16/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in myBloggie 2.1.6 and previous versions allow remote malicious users to execute arbitrary SQL commands via the (1) cat_id or (2) year parameter to index.php in a viewuser action, different vectors than CVE-2005-1500 and CVE-2005-4225.

Vulnerable Product Search on Vulmon Subscribe to Product

mywebland mybloggie

Exploits

source: wwwsecurityfocuscom/bid/24249/info myBloggie is prone to an SQL-injection vulnerability An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database This issue affects myBloggie 216 and earlier wwwexamplecom/apppath/indexphp?mode=viewuser& ...