CVE-2006-1123

D2KBlog <1.0.3 - SQL Injection

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in D2KBlog 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the memName parameter in a cookie.

Exploits (1)

exploitdb WORKING POC VERIFIED
by DevilBox · perlwebappsasp
https://www.exploit-db.com/exploits/1569

Scores

EPSS 0.0230
EPSS Percentile 84.8%

Details

Status published
Products (4)
d2ksoft/d2kblog 1.0
d2ksoft/d2kblog 1.0.1
d2ksoft/d2kblog 1.0.2
d2ksoft/d2kblog 1.0.3
Published Mar 09, 2006
Tracked Since Feb 18, 2026