4.3
CVSSv2

CVE-2008-6631

Published: 07/04/2009 Updated: 17/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in index.php in BlogPHP 2.0 allow remote malicious users to inject arbitrary web script or HTML via the (1) user parameter in a sendmessage action and the (2) username parameter when registering a new user, different vectors than CVE-2008-0679.

Vulnerable Product Search on Vulmon Subscribe to Product

blogphp blogphp 2.0

Exploits

source: wwwsecurityfocuscom/bid/29133/info BlogPHP is prone to multiple input-validation vulnerabilities, including a cross-site scripting issue, an HTML-injection issue, and a cookie-manipulation issue Attackers can exploit these issues to execute arbitrary script code in the context of the webserver, compromise the application, steal ...