VendorsDavethewebguybattle_blogall versions
Vulnerabilities

Davethewebguy Battle Blog

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2009-3718
SQL injection vulnerability in admin/authenticate.asp in Battle Blog 1.25 and 1.30 build 2 allows remote attackers to execute arbitrary SQL commands via the UserName parameter.
Published 2009-10-16 · Modified
7.51 PoCEPSS 0.020
CVE-2009-3719
Cross-site scripting (XSS) vulnerability in comment.asp in Battle Blog 1.25 and 1.30 build 2 allows remote attackers to inject arbitrary web script or HTML via a comment.
Published 2009-10-16 · Modified
4.31 PoCEPSS 0.015