Description
SQL injection vulnerability in viewcat.php in BitDamaged geoBlog MOD_1.0 allows remote attackers to execute arbitrary SQL commands, then steal credentials and upload files, via the cat parameter ($tmpCategory variable).
Affected products
- bitdamaged / geoblogmod_1.0 – mod_1.0
References
- MISChttp://www.securityfocus.com/bid/16249
- VENDOR_ADVISORYhttp://secunia.com/advisories/18504
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/24146
- MISChttp://evuln.com/vulns/33/summary.html
- MISChttp://www.osvdb.org/22463
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2006/0191
- MISChttp://securitytracker.com/id?1015493