Bo-blog Wind through 1.6.0-r allows SQL Injection via the admin.php/comments/batchdel/ comID parameter because this parameter is mishandled in the mode/admin.mode.php delBlockedBatch function.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-02-07T19:00:00Z

Updated: 2024-09-16T17:39:10.196Z

Reserved: 2019-02-07T00:00:00Z

Link: CVE-2019-7587

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-02-07T19:29:00.333

Modified: 2019-02-08T15:31:29.493

Link: CVE-2019-7587

cve-icon Redhat

No data.