Vulnonym.org

CVE-2008-2670 - Wire haired Blackboard

Description

Multiple SQL injection vulnerabilities in index.php in Insanely Simple Blog 0.5 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter or (2) the term parameter in a search action. NOTE: the current_subsection parameter is already covered by CVE-2007-3889.

Reference

http://chroot.org/exploits/chroot_uu_010 http://www.securityfocus.com/bid/29630 http://securityreason.com/securityalert/3938 https://www.exploit-db.com/exploits/5774 http://www.securityfocus.com/archive/1/493224/100/0/threaded