VYPR

Aoblogger

by Mike Helton

CVEs (3)

  • CVE-2006-0312Jan 19, 2006
    risk 0.04cvss epss 0.13

    create.php in aoblogger 2.3 allows remote attackers to bypass authentication and create new blog entries by setting the uza parameter to 1.

  • CVE-2006-0310Jan 19, 2006
    risk 0.04cvss epss 0.10

    Cross-site scripting (XSS) vulnerability in aoblogger 2.3 allows remote attackers to inject arbitrary Javascript via a javascript URI in the BBcode url tag.

  • CVE-2006-0311Jan 19, 2006
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in login.php in aoblogger 2.3 allows remote attackers to execute arbitrary SQL commands via the username parameter.