Back

CVE-2006-0249

SQL injection vulnerability in viewcat.php in BitDamaged geoBlog MOD_1.0 allows remote attackers to execute arbitrary SQL commands, then steal credentials and upload files, via the cat parameter ($tmpCategory variable).

Published: Jan 18, 2006 Modified: Jun 16, 2026
CWE-89

CVSS Metrics

Affected Products (1)

Vendor Product Version
bitdamaged geoblog mod_1.0

GitHub Security Advisory GHSA-w6rg-r4xx-pmx6

SQL injection vulnerability in viewcat.php in BitDamaged geoBlog MOD_1.0 allows remote attackers...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.29%

Top 32% most likely to be exploited

Threat Score 30.4 / 100

Data Sources

NVD EPSS GitHub