7.5
CVSSv2

CVE-2008-6180

Published: 19/02/2009 Updated: 11/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in system/nlb_user.class.php in NewLife Blogger 3.0 and previous versions, and possibly 3.3.1, allows remote malicious users to execute arbitrary SQL commands via the nlb3 cookie.

Vulnerable Product Search on Vulmon Subscribe to Product

newlife blogger newlife blogger

newlife blogger newlife blogger 3.3.1

Exploits

-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= NewLife Blogger <= v30 / Insecure Cookie Handling & SQL Injection Vulnerability -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= $ Program: NewLife Blogger $ Version: <= 30 $ File affected: system/nlb_userclassphp $ Downl ...