CVE-2007-3979
BlogSite Professional < 1.2 - SQL Injection via news_id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-3979. PoCs published by t0pP8uZz.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in BlogSite Professional, allowing an attacker to extract admin credentials via a crafted UNION-based SQL query. The PoC provides a direct URL to exploit the vulnerability without requiring authentication.
Description
SQL injection vulnerability in index.php in BlogSite Professional (aka Blog System) 1.x allows remote attackers to execute arbitrary SQL commands via the news_id parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in BlogSite Professional, allowing an attacker to extract admin credentials via a crafted UNION-based SQL query. The PoC provides a direct URL to exploit the vulnerability without requiring authentication.