Disclosure: bBlog 0.7.4 Multiple Vulnerabilities

[This was originally disclosed on the SourceForge bug tracker. VulnDB 15754, 15755, & 15756]

in 0.7.4:

The blog entry title field seems prone to cross site scripting (XSSattacks.

The blog/comment body text seems prone to XSS as well.

In the index.php script, the postid variable seems prone to SQL injection attacks.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Google photo

You are commenting using your Google account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s