Multiple SQL injection vulnerabilities in BetaParticle Blog 6.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to template_permalink.asp or (2) fldGalleryID parameter to template_gallery_detail.asp.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Betaparticle_blog | Betaparticle | 3.0 (including) | 3.0 (including) |
Betaparticle_blog | Betaparticle | 4.0 (including) | 4.0 (including) |
Betaparticle_blog | Betaparticle | 5.0 (including) | 5.0 (including) |
Betaparticle_blog | Betaparticle | 6.0 (including) | 6.0 (including) |