VendorsSaral Kaushiksaralblog1.0
Vulnerabilities

Saral Kaushik Saralblog 1.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2006-0345
Multiple SQL injection vulnerabilities in SaralBlog 1.0 allow remote attackers to execute arbitrary SQL commands via the search parameter to search.php. NOTE: the id/viewprofile.php issue is already covered by CVE-2005-4058.
Published 2006-01-21 · Modified
7.51 PoCEPSS 0.013
CVE-2006-0346
Cross-site scripting (XSS) vulnerability in SaralBlog 1.0 allows remote attackers to inject arbitrary web script or HTML via a website field in a new comment to view.php, which is not properly handled in the comment function in functions.php.
Published 2006-01-21 · Modified
4.3EPSS 0.014