Skip to content

J-Security Center

Latest Attack Object Updates
  • IDP Daily Update #1312
    posted: 11/18/08
  • NSM Daily Update #1312
    posted: 11/18/08
  • Deep Inspection 5.3r5 and above, 5.4, 6.0 #1312
    posted: 11/18/08
  • Deep Inspection 5.1, 5.2, 5.3r4 and below #1300
    posted: 11/18/08
  • Deep Inspection 5.0 #1132
    posted: 04/01/08
  • Antivirus
    posted: 11/17/08

Title: Simple PHP Blog 0.5.0 Multiple Remote Vulnerabilities

Severity: HIGH

Description:

Simple PHP Blog is PHP-based web-log application.

The application is prone to multiple remote vulnerabilities:

1. An information-disclosure vulnerability affects the 'config/user.php' script. Specifically, this issue will allow attackers to obtain usernames and password hashes for the affected application.

2. A vulnerability may allow attackers to execute arbitrary PHP code because the application fails to sanitize user-supplied input. Specifically, the application fails to sanitize user-supplied emoticons before uploading them onto the webserver.

Attackers can exploit these issues to obtain sensitive information or execute arbitrary PHP code within the context of the webserver process.

Simple PHP Blog 0.5.0 is vulnerable; other versions may also be affected.

Affected Products:

  • Simple PHP Blog Simple PHP Blog 0.5.0

References: