In the blog module (xipblog), an anonymous user can perform SQL injection. Even though the module has been patched in version 2.0.1, the version number was not incremented at the time.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view