vendor:
BetaParticle Blog
by:
nukedx
9
CVSS
HIGH
SQL Injection
89
CWE
Product Name: BetaParticle Blog
Affected Version From: 6.0 and prior
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: a:betaparticle:betaparticle_blog
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
BetaParticle Blog <= 6.0 Remote SQL Injection Vulnerability
BetaParticle Blog version 6.0 and prior are vulnerable to a remote SQL injection vulnerability. An attacker can exploit this vulnerability to gain access to the admin panel of the blog. The vulnerability is due to the application not properly sanitizing user-supplied input to the 'fldGalleryID' parameter in the 'template_gallery_detail.asp' script. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing malicious SQL statements to the vulnerable script. Successful exploitation will allow the attacker to gain access to the admin panel of the blog.
Mitigation:
Upgrade to the latest version of BetaParticle Blog.