← Back

Max.blog

max.blog

Vendor: Mzbservices • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mzbservices
1Max.blog
Apr 23, 2026
Feb 3, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in offline_auth.php in Max.Blog 1.0.6 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.
1Mzbservices
1Max.blog
Apr 23, 2026
Feb 2, 2009
N/A· v4
N/A· v3
6.4 MEDIUM· v2
delete.php in Max.Blog 1.0.6 does not properly restrict access, which allows remote attackers to delete arbitrary blog posts via a direct request.