Description
Incomplete blacklist vulnerability in default.asp in 8pixel.net Simple Blog 2.3 and earlier allows remote attackers to conduct SQL injection attacks via ">" characters in the id parameter, which are not filtered by the protection mechanism.
Affected products
- 8pixel.net / simple_blog2.0 – 2.0
- 8pixel.net / simple_blog2.1 – 2.1
- 8pixel.net / simple_blog2.2 – 2.2
- 8pixel.net / simple_blog2.3 – 2.3