CVE-2007-1899: SQL Injection
Multiple SQL injection vulnerabilities in myWebland myBloggie 2.1.6 allow remote attackers to execute arbitrary SQL commands via (1) the userid parameter in a viewuser action to index.php, and allow remote authenticated administrators to execute arbitrary SQL commands via (2) the postid parameter in an edit action to admin.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1899?
CVE-2007-1899 is considered a high severity vulnerability due to its potential for remote SQL injection attacks.
How do I fix CVE-2007-1899?
To fix CVE-2007-1899, you should upgrade myBloggie to a version that is not affected by this vulnerability.
What are the consequences of exploiting CVE-2007-1899?
Exploiting CVE-2007-1899 can allow attackers to execute arbitrary SQL commands, leading to data manipulation or unauthorized access.
Who is affected by CVE-2007-1899?
Users of myWebland myBloggie version 2.1.6 are affected by CVE-2007-1899.
Are remote attacks possible with CVE-2007-1899?
Yes, CVE-2007-1899 allows remote attackers to exploit SQL injection vulnerabilities.