VulnerabilityModified
CVE-2008-6250
SQL injection vulnerability in Comdev Web Blogger 4.1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the arcmonth parameter to a blog page.
MEDIUM 6.8EPSS 1.08%
Does this matter?
Lower severity and a low EPSS score (1.08%). Track it; it rarely justifies an emergency change on its own.
Description
SQL injection vulnerability in Comdev Web Blogger 4.1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the arcmonth parameter to a blog page.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.08% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- comdev/comdev web blogger
- Source
- cve@mitre.org
References
- http://e-rdc.org/v1/news.php?readmore=102Exploit
- http://secunia.com/advisories/31100Vendor Advisory
- http://www.securityfocus.com/archive/1/494412/100/0/threaded
- http://www.securityfocus.com/bid/30237
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43776
- https://www.exploit-db.com/exploits/6079
- http://e-rdc.org/v1/news.php?readmore=102Exploit
- http://secunia.com/advisories/31100Vendor Advisory
- http://www.securityfocus.com/archive/1/494412/100/0/threaded
- http://www.securityfocus.com/bid/30237
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43776
- https://www.exploit-db.com/exploits/6079
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.