ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-36972”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-36972
Published
2026-01-28
CVSS:
8.8
ShadowTrackr CVSS:
6.7
Summary:
SmartBlog 2.0.1 contains a blind SQL injection vulnerability in the 'id_post' parameter of the details controller that allows attackers to extract database information. Attackers can systematically test and retrieve database contents by injecting crafted SQL queries that compare character-by-character of database information.