7.5
CVSSv2

CVE-2008-3563

Published: 10/08/2008 Updated: 11/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Plogger 3.0 and previous versions allow remote malicious users to execute arbitrary SQL commands via (1) the checked array parameter to plog-download.php in an album action and (2) unspecified parameters to plog-remote.php, and (3) allow remote authenticated administrators to execute arbitrary SQL commands via the activate parameter to admin/plog-themes.php, related to theme_dir settings.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

plogger plogger 1.0

plogger plogger 2.0

plogger plogger 2.1

plogger plogger

Exploits

########################################################## # GulfTech Security Research August 05, 2008 ########################################################## # Vendor : Mike Johnson # URL : wwwploggerorg/ # Version : Plogger <= 30 # Risk : SQL Injection ########################################################## Desc ...