Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown

CVE-2024-13199

Disclosure Date: January 09, 2025 (last updated January 09, 2025)
A vulnerability classified as problematic was found in langhsu Mblog Blog System 3.5.0. Affected by this vulnerability is an unknown functionality of the file /search of the component Search Bar. The manipulation of the argument kw leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown

CVE-2024-13198

Disclosure Date: January 09, 2025 (last updated January 09, 2025)
A vulnerability classified as problematic has been found in langhsu Mblog Blog System 3.5.0. Affected is an unknown function of the file /login. The manipulation leads to observable response discrepancy. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown

CVE-2021-27280

Disclosure Date: May 08, 2023 (last updated October 08, 2023)
OS Command injection vulnerability in mblog 3.5.0 allows attackers to execute arbitrary code via crafted theme when it gets selected.
Attacker Value
Unknown

CVE-2021-46028

Disclosure Date: January 20, 2022 (last updated February 23, 2025)
In mblog <= 3.5.0 there is a CSRF vulnerability in the background article management. The attacker constructs a CSRF load. Once the administrator clicks a malicious link, the article will be deleted.
Attacker Value
Unknown

CVE-2020-19618

Disclosure Date: April 01, 2021 (last updated February 22, 2025)
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the post content field to /post/editing.
Attacker Value
Unknown

CVE-2020-19619

Disclosure Date: April 01, 2021 (last updated February 22, 2025)
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the signature field to /settings/profile.
Attacker Value
Unknown

CVE-2020-19617

Disclosure Date: April 01, 2021 (last updated February 22, 2025)
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the nickname field to /settings/profile.
Attacker Value
Unknown

CVE-2020-19616

Disclosure Date: April 01, 2021 (last updated February 22, 2025)
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the post header field to /post/editing.
Attacker Value
Unknown

CVE-2010-4937

Disclosure Date: October 09, 2011 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in the Amblog (com_amblog) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) articleid or (2) catid parameter to index.php.
0
Attacker Value
Unknown

CVE-2010-4876

Disclosure Date: October 07, 2011 (last updated October 04, 2023)
SQL injection vulnerability in viewpost.php in mBlogger 1.0.04 allows remote attackers to execute arbitrary SQL commands via the postID parameter.
0