WBBlog.Parameter.Remote.SQL.Injection

description-logoDescription

WBBlog has a SQL-injection vulnerability. A remote attacker could execute arbitrary SQL commands in the back-end database via a specially-crafted HTTP request with the e_id parameter in a viewentry cmd.

affected-products-logoAffected Products

WBBlog

Impact logoImpact

SQL injection.

recomended-action-logoRecommended Actions

Currently we are not aware of any official supplied fix for this issue.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2020-12-11 16.978