Multiple SQL injection vulnerabilities in index.php in Insanely Simple Blog 0.5 allow remote malicious users to execute arbitrary SQL commands via (1) the id parameter, or (2) the term parameter in a search action. NOTE: the current_subsection parameter is already covered by CVE-2007-3889.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
insanelysimple2 isblog 0.5 |