First published: Wed Aug 09 2006(Updated: )
Multiple SQL injection vulnerabilities in trackback.php in myWebland myBloggie 2.1.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) title, (2) url, (3) excerpt, or (4) blog_name parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
myWebland myBloggie | <=2.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4042 is considered to be of high severity due to its exploitation potential leading to arbitrary SQL command execution.
To fix CVE-2006-4042, upgrade to myWebland myBloggie version 2.1.5 or later.
CVE-2006-4042 allows remote attackers to exploit SQL injection vulnerabilities through multiple parameters such as title, url, excerpt, and blog_name.
CVE-2006-4042 affects myWebland myBloggie versions up to and including 2.1.4.
Website owners using vulnerable versions of myWebland myBloggie are at risk of being impacted by CVE-2006-4042.