CVE-2006-1778
Multiple SQL injection vulnerabilities in Jeremy Ashcraft Simplog 0.9.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) blogid parameter in (a) index.php and (b) archive.php, the (2) m and (3) y parameters in archive.php, and the (4) sql parameter in (c) server.php.
- Affected products
- Simplog
- Simplog
- ≤ 0.9.2
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 4.3% (90th percentile)
- NVD status
- Modified
- Published
- 2006-04-13
CVE-2006-1778 at NVD
1 known exploit for CVE-2006-1778
Proof-of-concept code and exploit modules indexed by Sploitus