Launchpad.net

CVE 2009-4801

EZ-Blog Beta 1 does not require authentication, which allows remote attackers to create or delete arbitrary posts via requests to PHP scripts.

See the CVE page on Mitre.org for more details.

References