7.5
CVSSv2

CVE-2009-4801

Published: 23/04/2010 Updated: 10/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

EZ-Blog Beta 1 does not require authentication, which allows remote malicious users to create or delete arbitrary posts via requests to PHP scripts.

Vulnerable Product Search on Vulmon Subscribe to Product

will kraft ez-blog -

Exploits

******* Salvatore "drosophila" Fresta ******* Application: EZ-Blog sourceforgenet/projects/ez-blog/ Version: Beta 1 Bug: * Multiple SQL Injection Exploitation: Remote Date: 1 Mar 2009 Discovered by: Salvatore "drosophila" Fresta Author: Salvatore " ...