vendor:
BlogSite Professional
by:
t0pP8uZz & xprog
5.5
CVSS
MEDIUM
SQL Injection
89
CWE
Product Name: BlogSite Professional
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
BlogSite Professional SQL Injection Vulnerability
The vulnerability allows an attacker to pull out admin/members login credentials by exploiting a SQL injection vulnerability in the BlogSite Professional application. The exploit uses a crafted URL to perform a UNION SELECT statement and retrieve the username and password from the websiteadmin_admin_users table.
Mitigation:
To mitigate this vulnerability, the vendor should release a patch or update to fix the SQL injection vulnerability.