vendor:
Blogcms
by:
Alexandr Polyakov, Stas Svistunovich
8.5
CVSS
HIGH
SQL Injestions, SiXSS, XSS
89, 79, 79
CWE
Product Name: Blogcms
Affected Version From: Blogcms 4.2.1b
Affected Version To: Blogcms 4.2.2b
Patch Exists: YES
Related CWE: N/A
CPE: a:blogcms:blogcms
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
DSECRG-08-003
Blogcms system has multiple security vulnerabilities: 1. Multiple SQL Injections, 2. Multiple Linked XSS, 3. Multiple Linked SiXSS. Attacker can inject SQL code in index.php. Parameter name 'blogid' and in module /blogcms/action.php. POST parameter name 'user'. Linked XSS vulnerability found in /photo/admin.php and /photo/index.php attacker can inject XSS script in URL. Linked SiXSS vulnerability found in /photo/admin.php and /photo/index.php attacker can inject XSS script in URL.
Mitigation:
Vendor released new version of Blogcms 4.2.2b