CVE-2008-2963
Published Jul 2, 2008
Last updated 7 years ago
Overview
- Description
- Multiple SQL injection vulnerabilities in MyBlog allow remote attackers to execute arbitrary SQL commands via the (1) view parameter to (a) index.php, and the (2) id parameter to (b) member.php and (c) post.php.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.8
- Impact score
- 6.4
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-89
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:myblog:myblog:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5707DF3F-954A-44ED-A876-99E8B75DE6C3" } ], "operator": "OR" } ] } ]