SQL injection vulnerability in the blogwriter module 2.0 for Miniweb allows remote attackers to execute arbitrary SQL commands via the historymonth parameter to index.php.
References
Configurations
History
21 Nov 2024, 00:46
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/30085 - Vendor Advisory | |
References | () http://www.securityfocus.com/bid/29061 - Exploit | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/42220 - | |
References | () https://www.exploit-db.com/exploits/5548 - |
Information
Published : 2008-05-14 17:20
Updated : 2025-04-09 00:30
NVD link : CVE-2008-2197
Mitre link : CVE-2008-2197
CVE.ORG link : CVE-2008-2197
JSON object : View
Products Affected
miniweb2
- blog_writer
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')