This application requires Javascript for optimal performance.

Bit.5.Blog.Index.PHP.SQL.Injection

Release Date

Nov 03, 2011

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt against a Stored Procedure SQL Injection vulnerability in Bit 5 Blog.

The vulnerability is a result of the failure of some methods to properly sanitize user input parameters. It may allow an attacker to execute arbitrary commands on a vulnerable system by injecting arbitrary SQL statements into stored procedures.

Affected Products

Bit 5 Blog 8.1

Recommended Actions

Currently we are not aware of any vendor supplied patches for this issue.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2006-0320

Reference: VID-29625