Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

CafeLog b2 WebLog Tool SQL Injection Vulnerability

CafeLog b2 WebLog Tool allows users to generate news pages and weblogs dynamically. It uses PHP and a MySQL database to generate dynamic pages.

The b2 WebLog Tool does not properly sanitize data that is sent to the tableposts variable. This could allow an attacker to modify the logic of SQL queries, allowing for execution of commands on the database.







 

Privacy Statement
Copyright 2008, SecurityFocus