VYPR

Brewblogger

by Brewblogger

CVEs (2)

  • CVE-2008-6911Aug 6, 2009
    risk 0.03cvss epss 0.00

    SQL injection vulnerability in the authenticateUser function in includes/authentication.inc.php in BrewBlogger (BB) 2.1.0.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the loginUsername parameter to includes/logincheck.inc.php. NOTE: some of these details are obtained from third party information.

  • CVE-2006-5889Nov 14, 2006
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in printLog.php in BrewBlogger (BB) 1.3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.