CVE-2007-1899

myWebland myBloggie 2.1.6 - SQL Injection via User ID Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-1899. PoCs published by Jesper Jurcenoks.

AI-analyzed exploit summary The exploit demonstrates SQL injection vulnerabilities in myBloggie 2.1.6, allowing attackers to extract admin credentials via crafted POST requests. It includes two distinct attack vectors, one targeting user view and another combining SQLi with XSS.

Description

Multiple SQL injection vulnerabilities in myWebland myBloggie 2.1.6 allow remote attackers to execute arbitrary SQL commands via (1) the user_id parameter in a viewuser action to index.php, and allow remote authenticated administrators to execute arbitrary SQL commands via (2) the post_id parameter in an edit action to admin.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Jesper Jurcenoks · textwebappsphp
https://www.exploit-db.com/exploits/5975

The exploit demonstrates SQL injection vulnerabilities in myBloggie 2.1.6, allowing attackers to extract admin credentials via crafted POST requests. It includes two distinct attack vectors, one targeting user view and another combining SQLi with XSS.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: myBloggie 2.1.6
No auth needed
Prerequisites: PHP magic_quotes_gpc set to Off · register_globals set to On
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (4)

Core 4
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30892
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5975
Various Sources x_refsource_misc
http://descriptions.securescout.com/tc/17969
Various Sources x_refsource_misc
http://www.netvigilance.com/advisory0040

Scores

EPSS 0.0092
EPSS Percentile 55.5%

Details

CWE
CWE-89
Status published
Products (1)
mywebland/mybloggie 2.1.6
Published Jul 09, 2008
Tracked Since Feb 18, 2026