CVE-2008-0360
Multiple SQL injection vulnerabilities in BLOG:CMS 4.2.1b allow remote attackers to execute arbitrary SQL commands via (1) the blogid parameter to index.php, (2) the user parameter to action.php, or (3) the field parameter to…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.06%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple SQL injection vulnerabilities in BLOG:CMS 4.2.1b allow remote attackers to execute arbitrary SQL commands via (1) the blogid parameter to index.php, (2) the user parameter to action.php, or (3) the field parameter to admin/plugins/table/index.php.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.06% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- blog cms/blog cms
- Source
- cve@mitre.org
References
- http://blogcms.com/wiki/changelog
- http://marc.info/?l=bugtraq&m=120049816924383&w=2Exploit
- http://secunia.com/advisories/28523Vendor Advisory
- http://www.securityfocus.com/bid/27317Exploit, Patch
- https://www.exploit-db.com/exploits/4919
- http://blogcms.com/wiki/changelog
- http://marc.info/?l=bugtraq&m=120049816924383&w=2Exploit
- http://secunia.com/advisories/28523Vendor Advisory
- http://www.securityfocus.com/bid/27317Exploit, Patch
- https://www.exploit-db.com/exploits/4919
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.