Vulnerabilities
Vulnerable Software
Mywebland:  >> Mybloggie  >> 2.1.6  Security Vulnerabilities
Multiple SQL injection vulnerabilities in myWebland myBloggie 2.1.6 allow remote attackers to execute arbitrary SQL commands via (1) the user_id parameter in a viewuser action to index.php, and allow remote authenticated administrators to execute arbitrary SQL commands via (2) the post_id parameter in an edit action to admin.php.
CVSS Score
5.1
EPSS Score
0.005
Published
2008-07-09
myWebland myBloggie 2.1.6 allow remote attackers to obtain sensitive information via (1) an invalid year parameter to calendar.php, reached through index.php; (2) a direct request to common.php; and (3) a mode array parameter in the query string to login.php, which reveal the installation path in various error messages.
CVSS Score
5.3
EPSS Score
0.003
Published
2008-07-09
Cross-site request forgery (CSRF) vulnerability in admin.php in myWebland myBloggie 2.1.6 allows remote attackers to perform edit actions as administrators. NOTE: this can be leveraged to execute SQL commands by also exploiting CVE-2007-1899.
CVSS Score
5.1
EPSS Score
0.003
Published
2008-07-09


Contact Us

Shodan ® - All rights reserved