← Back

Mzbservices

mzbservices

2 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Max.blog
max.blog

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mzbservices
1Max.blog
Apr 23, 2026
Feb 3, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in offline_auth.php in Max.Blog 1.0.6 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.
1Mzbservices
1Max.blog
Apr 23, 2026
Feb 2, 2009
N/A· v4
N/A· v3
6.4 MEDIUM· v2
delete.php in Max.Blog 1.0.6 does not properly restrict access, which allows remote attackers to delete arbitrary blog posts via a direct request.