CVE-2005-2009

Ublog Reload - SQL Injection

Title source: rule
STIX 2.1

Description

Multiple SQL injection vulnerabilities in Ublog Reload 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) ci, (2) d, or (3) m parameter to index.asp, or the (4) bi parameter to blog_comment.asp.

Exploits (2)

exploitdb WRITEUP VERIFIED
by Dedi Dwianto · textwebappsasp
https://www.exploit-db.com/exploits/25843
exploitdb WRITEUP VERIFIED
by Dedi Dwianto · textwebappsasp
https://www.exploit-db.com/exploits/25844

References (3)

Core 3
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=111928552304897&w=2
Exploit, Vendor Advisory x_refsource_misc
http://echo.or.id/adv/adv18-theday-2005.txt
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2005/0818

Scores

EPSS 0.0100
EPSS Percentile 77.1%

Details

Status published
Products (1)
ublog/reload 1.0.5
Published Jun 20, 2005
Tracked Since Feb 18, 2026