CVE

Id
24802  
CVE No.
CVE-2007-1445  
Status
Candidate  
Description
SQL injection vulnerability in the heme preview feature for default.asp in BP Blog 7.0 through 7.0.2 allows remote attackers to execute arbitrary SQL commands via the layout parameter.  
Phase
Assigned (20070313)  
Votes
None (candidate not yet proposed)  
Comments