vendor:
LulieBlog
by:
ka0x
7.5
CVSS
HIGH
Remote Admin Bypass
89
CWE
Product Name: LulieBlog
Affected Version From: 1.0.1
Affected Version To: 1.0.1
Patch Exists: NO
Related CWE: N/A
CPE: a:lulieblog:lulieblog:1.0.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
LulieBlog 1.0.1 (delete id) Remote Admin Bypass Vulnerability
The bug will allow an attacker to accept sent comments in the articles, erase comments and delete articles. The vulnerability is caused by the lack of proper input validation in the comment_accepter.php, comment_refuser.php and article_suppr.php scripts, which allows an attacker to inject malicious SQL queries. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing malicious SQL queries to the vulnerable scripts.
Mitigation:
Input validation should be implemented to prevent malicious SQL queries from being injected into the vulnerable scripts.