CVE

Id
32787  
CVE No.
CVE-2008-2670  
Status
Candidate  
Description
Multiple SQL injection vulnerabilities in index.php in Insanely Simple Blog 0.5 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter, or (2) the term parameter in a search action. NOTE: the current_subsection parameter is already covered by CVE-2007-3889.  
Phase
Assigned (20080611)  
Votes
None (candidate not yet proposed)  
Comments