index.php in myWebland myBloggie 2.1.4 and earlier allows remote attackers to obtain sensitive information via a query that only specifies the viewdate mode, which reveals the table prefix in a SQL error message.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mybloggie | Mywebland | * | 2.1.4 (including) |
Mybloggie | Mywebland | 2.1.1 (including) | 2.1.1 (including) |
Mybloggie | Mywebland | 2.1.2 (including) | 2.1.2 (including) |
Mybloggie | Mywebland | 2.1.3 (including) | 2.1.3 (including) |
Mybloggie | Mywebland | 2.1.3_beta (including) | 2.1.3_beta (including) |