|
|
Info |
Last Modified |
| 3 months ago |
|
|
|
|
Description |
Geeklog contains a flaw that may allow remote attackers to obtain sensitive information. The issue is caused by any number of SQL Injection attempts in seven different scripts. While the SQL Injection attempt will fail, the information Geeklog may disclose in the error message could be sensitive and help an attacker launch more focused attacks.
|
|
Classification |
Attack Type:
Information Disclosure
|
|
Solution |
Upgrade to version 1.3.8-1sr1 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
|
|
Products |
|
Geeklog
 |
1.3.5 |
1.3.7 |
1.3.8 |
|
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|