VYPR

Geoblog

by Bitdamaged

CVEs (3)

  • CVE-2007-4047Jul 27, 2007
    risk 0.03cvss epss 0.03

    geoBlog (aka BitDamaged) 1 does not require authentication for (1) deletecomment.php, (2) deleteblog.php, and (3) listcomment.php in admin/, which allows remote attackers to delete arbitrary comments, delete arbitrary blogs, and have other unspecified impact via a request with a…

  • CVE-2006-2177May 4, 2006
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in viewcat.php in geoBlog 1.0 allows remote attackers to inject arbitrary web script or HTML via the cat parameter.

  • CVE-2006-0249Jan 18, 2006
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in viewcat.php in BitDamaged geoBlog MOD_1.0 allows remote attackers to execute arbitrary SQL commands, then steal credentials and upload files, via the cat parameter ($tmpCategory variable).