从这个网页截图中获取到的关于漏洞的关键信息如下: Severity High Date January 28, 2026 Affected Software SmartBlog 2.0.1 CVE Identifier VULNCHECK-2020-36972 CWE Identifier CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVSS Score 7.5 (CVSS:3.1/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N) References ExploitDB-48995 SmartBlog GitHub Repository Credit C0wnuts Description SmartBlog 2.0.1 contains a blind SQL injection vulnerability in the 'id_post' parameter of the details controller that allows attackers to extract database information. Attackers can systematically test and retrieve database contents by injecting crafted SQL queries that compare character-by-character of database information.