CVE-2010-4856

xWeblog 2.2 - SQL Injection

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in arsiv.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via the tarih parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by ZoRLu · pythonwebappsasp
https://www.exploit-db.com/exploits/15219

References (1)

Core 1
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/15219

Scores

EPSS 0.0027
EPSS Percentile 50.6%

Details

CWE
CWE-89
Status published
Products (1)
aspindir/xweblog 2.2
Published Oct 05, 2011
Tracked Since Feb 18, 2026