CVE-2023-43381

SQL Injection vulnerability in Tianchoy Blog v.1.8.8 allows a remote attacker to obtain sensitive information via the id parameter in the login.php
Configurations

Configuration 1 (hide)

cpe:2.3:a:tianchoy:blog:1.8.8:*:*:*:*:*:*:*

History

21 Nov 2024, 08:24

Type Values Removed Values Added
References () https://gist.github.com/Chiaki2333/59ef607c3eb3a7b4db1537705d05e4d1 - Third Party Advisory () https://gist.github.com/Chiaki2333/59ef607c3eb3a7b4db1537705d05e4d1 - Third Party Advisory
References () https://github.com/Chiaki2333/vulnerability/blob/main/tianchoy-blog-sql-login.php.md - Exploit, Third Party Advisory () https://github.com/Chiaki2333/vulnerability/blob/main/tianchoy-blog-sql-login.php.md - Exploit, Third Party Advisory

29 Sep 2023, 15:29

Type Values Removed Values Added
First Time Tianchoy blog
Tianchoy
CPE cpe:2.3:a:tianchoy:blog:1.8.8:*:*:*:*:*:*:*
CWE CWE-89
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
References (MISC) https://gist.github.com/Chiaki2333/59ef607c3eb3a7b4db1537705d05e4d1 - (MISC) https://gist.github.com/Chiaki2333/59ef607c3eb3a7b4db1537705d05e4d1 - Third Party Advisory
References (MISC) https://github.com/Chiaki2333/vulnerability/blob/main/tianchoy-blog-sql-login.php.md - (MISC) https://github.com/Chiaki2333/vulnerability/blob/main/tianchoy-blog-sql-login.php.md - Exploit, Third Party Advisory

27 Sep 2023, 15:19

Type Values Removed Values Added
New CVE

Information

Published : 2023-09-27 15:19

Updated : 2024-11-21 08:24


NVD link : CVE-2023-43381

Mitre link : CVE-2023-43381

CVE.ORG link : CVE-2023-43381


JSON object : View

Products Affected

tianchoy

  • blog
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')