Summary
Yap Blog is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue may allow an attacker to compromise the application and the underlying system
other attacks are also
possible.
Versions prior to Yap Blog 1.1.1 are vulnerable.
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2008-1370 -
CVSS Base Score: 6.8
AV:N/AC:M/Au:N/C:P/I:P/A:P
Related Vulnerabilities
- A4Desk Event Calendar 'eventid' Parameter SQL Injection Vulnerability
- Apache Struts2/XWork Remote Command Execution Vulnerability
- Abtp Portal Project 'ABTPV_BLOQUE_CENT' Parameter Local and Remote File Include Vulnerabilities
- Apache Archiva Cross Site Request Forgery Vulnerability
- Apache Tomcat Information Disclosure Vulnerability