vendor:
Eggblog
by:
nukedx
7.5
CVSS
HIGH
Remote SQL injection
89
CWE
Product Name: Eggblog
Affected Version From: 3.0.6
Affected Version To: 3.x
Patch Exists: YES
Related CWE: N/A
CPE: a:eggblog:eggblog
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
Discovered in 2009
Eggblog <= 3.x Multiple Remote Vulnerabilities
Eggblog <= 3.0.6 (rss/posts.php id) Remote SQL injection allows an attacker to list all users and passwords by sending a specially crafted request to the vulnerable server.
Mitigation:
Upgrade to the latest version of Eggblog