Vulnerabilities (CVE)

Filtered by vendor Brewblogger Subscribe
Filtered by product Brewblogger
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-6911 1 Brewblogger 1 Brewblogger 2024-02-28 6.8 MEDIUM N/A
SQL injection vulnerability in the authenticateUser function in includes/authentication.inc.php in BrewBlogger (BB) 2.1.0.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the loginUsername parameter to includes/logincheck.inc.php. NOTE: some of these details are obtained from third party information.
CVE-2006-5889 1 Brewblogger 1 Brewblogger 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in printLog.php in BrewBlogger (BB) 1.3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.