7.5
CVSSv2

CVE-2008-3588

Published: 11/08/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in phsBlog 0.1.1 allow remote malicious users to execute arbitrary SQL commands via the (1) eid parameter to comments.php, (2) cid parameter to index.php, and the (3) urltitle parameter to entries.php.

Vulnerable Product Search on Vulmon Subscribe to Product

phsblog phsblog 0.1.1

Exploits

##################################################################################### # # Name : phsBlog v011 Multiple Remote SQL Injection Vulnerabilities # Author : cOndemned [Dark-Coders member] # Greetz : ZaBeaTy, GregStar, str0ke, 0in, suN8Hclf, ixos, TBH, Avantura :** # ###################################################### ...