Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2020-23327

Disclosure Date: April 04, 2023 (last updated February 24, 2025)
Cross Site Scripting vulnerability found in ZblogCN ZblogPHP v.1.0 allows a local attacker to execute arbitrary code via a crafted payload in title parameter of the module management model.
Attacker Value
Unknown

CVE-2006-0372

Disclosure Date: January 22, 2006 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in config.php in Insane Visions BlogPHP, possibly 1.0, allow remote attackers to execute arbitrary SQL commands via the (1) blogphp_username or (2) blogphp_password parameter in a cookie.
0
Attacker Value
Unknown

CVE-2006-0318

Disclosure Date: January 19, 2006 (last updated February 22, 2025)
SQL injection vulnerability in index.php in BlogPHP 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter in a login action.
0