Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-2184

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2008-2184
Last Modified 02 Apr 2009 01:34:08
Published 13 May 2008 06:20:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2008-2184

Summary

Multiple SQL injection vulnerabilities in SMartBlog (aka SMBlog) 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) mois, (2) an, (3) jour, and (4) id parameters to index.php, and the (5) login parameter to gestion/logon.php, different vectors than CVE-2008-2183. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Vulnerable Systems

Application

  • Toocharger Smartblog 1.3


References

XF - smartblog-logon-sql-injection(42245)

XF - smartblog-index-logon-sql-injection(42190)

BID - 29043

SECUNIA - 30057


Last Updated: 27 May 2016 10:47:46