Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple SQL injection vulnerabilities in myBloggie 2.1.1 allow remote attackers to execute arbitrary SQL commands via (1) the keyword parameter in search.php; or (2) the date_no parameter in viewdate mode, (3) the cat_id parameter in viewcat mode, the (4) month_no or (5) year parameter in viewmonth mode, or (6) post_id parameter in viewid mode to index.php. NOTE: item (1) was discovered to affect 2.1.3 as well.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MyBloggie多个输入验证漏洞
Vulnerability Description
myBloggie 2.1.1中存在多个SQL注入漏洞,远程攻击者可以通过(1)在search.php中的keyword参数,(2)在viewdate模式中的date_no参数,(3)在viewcat模式中的cat_id参数,在viewmonth模式中的(4)month_no或(5)year参数,或(6)在viewid模式中的post_id参数,执行任意SQL命令。
CVSS Information
N/A
Vulnerability Type
N/A