Show filters
35 Total Results
Displaying 11-20 of 35
Sort by:
Attacker Value
Unknown

CVE-2008-2962

Disclosure Date: July 02, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in MyBlog allow remote attackers to inject arbitrary web script or HTML via the (1) s and (2) sort parameters to index.php, and the (3) id parameter to post.php.
0
Attacker Value
Unknown

CVE-2008-2963

Disclosure Date: July 02, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in MyBlog allow remote attackers to execute arbitrary SQL commands via the (1) view parameter to (a) index.php, and the (2) id parameter to (b) member.php and (c) post.php.
0
Attacker Value
Unknown

CVE-2007-3194

Disclosure Date: June 12, 2007 (last updated November 08, 2023)
Multiple PHP remote file inclusion vulnerabilities in myBloggie 2.1.5 allow remote attackers to execute arbitrary PHP code via a URL in the bloggie_root_path parameter to (1) config.php; (2) db.php, (3) template.php, (4) functions.php, and (5) classes.php in includes/; (6) viewmode.php; and (7) blog_body.php. NOTE: another researcher disputes the vulnerability because the files are protected against direct requests, contain no relevant include statements, or do not exist
0
Attacker Value
Unknown

CVE-2007-3003

Disclosure Date: June 04, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in myBloggie 2.1.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat_id or (2) year parameter to index.php in a viewuser action, different vectors than CVE-2005-1500 and CVE-2005-4225.
0
Attacker Value
Unknown

CVE-2007-2081

Disclosure Date: April 18, 2007 (last updated October 04, 2023)
MyBlog 0.9.8 and earlier allows remote attackers to bypass authentication requirements via the admin cookie parameter to certain admin files, as demonstrated by admin/settings.php.
0
Attacker Value
Unknown

CVE-2007-2082

Disclosure Date: April 18, 2007 (last updated October 04, 2023)
Direct static code injection vulnerability in admin/settings.php in MyBlog 0.9.8 and earlier allows remote authenticated admin users to inject arbitrary PHP code via the content parameter, which can be executed by accessing index.php. NOTE: a separate vulnerability could be leveraged to make this issue exploitable by remote unauthenticated attackers.
0
Attacker Value
Unknown

CVE-2007-1990

Disclosure Date: April 12, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in games.php in Sam Crew MyBlog, possibly 1.0 through 1.6, allows remote attackers to execute arbitrary PHP code via a URL in the id parameter, a different vector than CVE-2007-1968. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2007-1968

Disclosure Date: April 11, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in games.php in Sam Crew MyBlog, possibly 1.0 through 1.6, allows remote attackers to execute arbitrary PHP code via a URL in the scoreid parameter.
0
Attacker Value
Unknown

CVE-2007-1969

Disclosure Date: April 11, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in admin/modify.php in Sam Crew MyBlog remote attackers to inject arbitrary web script or HTML via the id parameter.
0
Attacker Value
Unknown

CVE-2007-0353

Disclosure Date: January 19, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in (1) index.php and (2) login.php in myBloggie 2.1.5 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO string.
0