Vulnerabilities
Vulnerable Software
Drumster:  >> Blogme  >> 3.0  Security Vulnerabilities
SQL injection vulnerability in archshow.asp in BlogMe 3.0 allows remote attackers to execute arbitrary SQL commands via the var parameter, a different vector than CVE-2006-5976.
CVSS Score
7.5
EPSS Score
0.011
Published
2007-05-14
Multiple cross-site scripting (XSS) vulnerabilities in comments.asp in BlogMe 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) URL, or (3) Comments field.
CVSS Score
6.8
EPSS Score
0.101
Published
2006-11-20
Multiple SQL injection vulnerabilities in admin_login.asp in BlogMe 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) Username or (2) Password field. NOTE: some of these details are obtained from third party information.
CVSS Score
7.5
EPSS Score
0.015
Published
2006-11-20


Contact Us

Shodan ® - All rights reserved