>> Battle Blog "Entry" Parameter Remote SQL Injection Vulnerability
Title : Battle Blog "Entry" Parameter Remote SQL Injection Vulnerability VUPEN ID : VUPEN/ADV-2008-1737 CVE ID : CVE-2008-2626 - CVE-2008-2685 CWE ID : CWE-89
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-06-04
Technical Description
A vulnerability has been identified in Battle Blog, which could be exploited by attackers to manipulate and inject SQL queries. This issue is caused by input validation errors in the "comment.asp" and "article.asp" scripts when processing the "Entry" parameter, which could be exploited by malicious people to conduct SQL injection attacks and gain knowledge of sensitive information.