A Blog is a modestly represented blogging platform with a concentrated vulnerability footprint centered on its single product. The exposure reflects typical application-layer concerns for content-management and publishing software. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by A Blog over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-5092HIGH PHP remote file inclusion vulnerability in navigation/menu.php in A-Blog 2 allows remote attackers to execute arbitrary PHP code via a URL in the navigation_start parameter. | Sep 29, 2006 | 7.5 | 32 | NO | YES |
CVE-2010-4917HIGH SQL injection vulnerability in sources/search.php in A-Blog 2.0 allows remote attackers to execute arbitrary SQL commands via the words parameter. | Oct 8, 2011 | 7.5 | 31 | NO | YES |
CVE-2006-5135HIGH Multiple PHP remote file inclusion vulnerabilities in A-Blog 2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) open_box, (2) middle_box, and (3) close_box | Oct 3, 2006 | 7.5 | 31 | NO | YES |
CVE-2008-0677HIGH SQL injection vulnerability in blog.php in A-Blog 2 allows remote attackers to execute arbitrary SQL commands via the id parameter in a news action. | Feb 12, 2008 | 7.5 | 30 | NO | YES |
CVE-2008-0676MEDIUM Cross-site scripting (XSS) vulnerability in search.php in A-Blog 2 allows remote attackers to inject arbitrary web script or HTML via the words parameter. | Feb 12, 2008 | 4.3 | 24 | NO | YES |
CVE-2006-6729MEDIUM Cross-site scripting (XSS) vulnerability in a-blog 1.51 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Dec 26, 2006 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by A Blog.
Media articles that mention a CVE ID that affects a product developed by A Blog — matched by CVE ID, not by vendor name.