Back to Database
Status published
High
CVE-2005-4049
Multiple SQL injection vulnerabilities in Blog System 1.2 allow remote...
Vulnerability Description
Multiple SQL injection vulnerabilities in Blog System 1.2 allow remote attackers to execute arbitrary SQL commands via (1) the cat parameter in index.php and (2) the note parameter in blog.php.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2005-4049
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/bid/15719/
- http://www.osvdb.org/21454
- http://www.vupen.com/english/advisories/2005/2767
- http://www.securityfocus.com/archive/1/418640/100/0/threaded
- http://securitytracker.com/id?1015310
- http://securityreason.com/securityalert/230
- http://secunia.com/advisories/17893/
- http://pridels0.blogspot.com/2005/12/blog-system-v12-sql-inj-vuln.html
- http://www.osvdb.org/21453
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23430
More from netart media
View All →CVE-2008-6111
SQL injection vulnerability in blog.php in NetArt Media Vlog System...
High
7.5
CVE-2008-5311
SQL injection vulnerability in image.php in NetArt Media Blog System...
High
7.5
CVE-2008-5310
SQL injection vulnerability in image.php in NetArt Media Car Portal...
High
7.5
CVE-2008-5309
SQL injection vulnerability in NetArt Media Real Estate Portal 1.2...
High
7.5
CVE-2007-3979
SQL injection vulnerability in index.php in BlogSite Professional (aka Blog...
Medium
6.8
Affected Vendor
netart media
View all reports →Affected Software
blog system
Vulnerable Versions:
1.2
Timeline
Official Publish:
December 7th, 2005
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.