This application requires Javascript for optimal performance.

GeoBlog.Cat.Parameter.SQL.Injection

Release Date

Dec 08, 2009

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt against an SQL injection vulnerability in viewcat.php in BitDamaged geoBlog.

The vulnerability is caused by an error when the vulnerable software handles a specially crafted HTTP request. It allows a remote attacker to execute arbitrary SQL commands.

Affected Products

geoBLog geoBlog MOD_1.0

Recommended Actions

Update to the latest versions:

http://sourceforge.net/projects/bitdamaged/

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2006-0249

Reference/s

http://www.securityfocus.com/bid/16249 (BugTraq)
http://www.frsirt.com/english/advisories/2006/0191 (FrSIRT)

Reference: VID-17979