This application requires Javascript for optimal performance.

LBlog.Comments.ASP.Path.SQL.Injection

Release Date

Nov 03, 2011

Severity

high

Impact

System Compromise.

Description

This indicates a possible attempt to exploit a SQL Injection vulnerability in LBlog

The vulnerability may allow remote attackers to execute arbitrary SQL statements via a crafted "id" parameter. An attacker can leverage this issue to manipulate and disclose database contents, leading to system compromise.

Affected Products

LBlog 1.05

Recommended Actions

The vendor has released version 2.0 to address this issue.
http://www.lblog.dk

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2006-4284

Reference: VID-29659