Loading vulnerability details…
CVSS v3.1
N/A
EPSS
2.93%
Published
Jan 19, 2006
Modified
Jun 16, 2026
Public PoC / Exploit (2)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
create.php in aoblogger 2.3 allows remote attackers to bypass authentication and create new blog entries by setting the uza parameter to 1.
Affected Products (1)
References (14)