7.5
CVSSv2

CVE-2008-2670

Published: 12/06/2008 Updated: 11/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in index.php in Insanely Simple Blog 0.5 allow remote malicious users to execute arbitrary SQL commands via (1) the id parameter, or (2) the term parameter in a search action. NOTE: the current_subsection parameter is already covered by CVE-2007-3889.

Vulnerable Product Search on Vulmon Subscribe to Product

insanelysimple2 isblog 0.5

Exploits

_____ _ _ _____ _____ _____ _____ / ___| |_| | _ \| _ | _ |_ _| | (___| _ | [_)_/| (_) | (_) | | | \_____|_| |_|_| |_||_____|_____| |_| C H R O O T SECURITY GROUP - -- ----- --- -- -- ---- --- -- - wwwchrootorg _ _ _ _____ ____ ____ __ _ ...