CVE-2005-4225
Multiple "potential" SQL injection vulnerabilities in myBloggie 2.1.3 beta might allow remote attackers to execute arbitrary SQL commands via (1) the category parameter in add.php, (2) the cat_desc parameter in addcat.php, (3) the level and user…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.01%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple "potential" SQL injection vulnerabilities in myBloggie 2.1.3 beta might allow remote attackers to execute arbitrary SQL commands via (1) the category parameter in add.php, (2) the cat_desc parameter in addcat.php, (3) the level and user parameters in adduser.php, (4) the post_id parameter in del.php, (5) the cat_id parameter in delcat.php, (6) the comment_id parameter in delcomment.php, (7) the id parameter in deluser.php, (8) the post_id and category parameter in edit.php, (9) the cat_id and cat_desc parameters in editcat.php, and (10) the id, level, and user parameters in edituser.php. NOTE: the username/login.php vector is already identified by CVE-2005-2838.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.01% probability · 80th percentile
- CISA KEV
- Not listed
- Affected
- mywebland/mybloggie
- Source
- cve@mitre.org
References
- http://glide.stanford.edu/yichen/research/sec.pdf
- http://secunia.com/advisories/18024/Vendor Advisory
- http://www.osvdb.org/21659
- http://www.osvdb.org/21660
- http://www.osvdb.org/21661
- http://www.osvdb.org/21662
- http://www.osvdb.org/21663
- http://www.osvdb.org/21664
- http://www.osvdb.org/21665
- http://www.osvdb.org/21666
- http://www.osvdb.org/21667
- http://www.osvdb.org/21668
- http://www.osvdb.org/21669
- http://www.osvdb.org/21670
- http://www.securityfocus.com/archive/1/419280/100/0/threaded
- http://www.securityfocus.com/archive/1/419487/100/0/threaded
- http://www.vupen.com/english/advisories/2005/2862
- http://glide.stanford.edu/yichen/research/sec.pdf
- http://secunia.com/advisories/18024/Vendor Advisory
- http://www.osvdb.org/21659
- http://www.osvdb.org/21660
- http://www.osvdb.org/21661
- http://www.osvdb.org/21662
- http://www.osvdb.org/21663
- http://www.osvdb.org/21664
- http://www.osvdb.org/21665
- http://www.osvdb.org/21666
- http://www.osvdb.org/21667
- http://www.osvdb.org/21668
- http://www.osvdb.org/21669
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.