CVE-2005-3076: High severity Simplog Simplog vulnerability
Published Sep 27, 2005
·Updated
Simplog 0.9.1 might allow remote attackers to execute arbitrary SQL commands or trigger SQL error messages via invalid (1) pid, (2) blogid, (3) cid, or (4) m parameters to archive.php, or the (5) blogid parameter to blogadmin.php.
Affected Software
1 affected component
Simplog Simplog=0.9.1
Event History
Sep 27, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3076?
CVE-2005-3076 is classified as a medium severity vulnerability, allowing for the execution of arbitrary SQL commands.
2
How do I fix CVE-2005-3076?
To fix CVE-2005-3076, you should upgrade Simplog to version 0.9.2 or later, which addresses this vulnerability.
3
What software is affected by CVE-2005-3076?
CVE-2005-3076 affects Simplog version 0.9.1.
4
What types of parameters are exploited in CVE-2005-3076?
CVE-2005-3076 can be exploited via the pid, blogid, cid, or m parameters in archive.php, and the blogid parameter in blogadmin.php.
5
Can CVE-2005-3076 be exploited remotely?
Yes, CVE-2005-3076 can be exploited remotely by an attacker through crafted requests.