First published: Tue May 27 2008(Updated: )
SQL injection vulnerability in comment.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows remote attackers to execute arbitrary SQL commands via the rid parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
e107 BLOG Engine | =2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2455 has been classified as a medium severity vulnerability due to its potential for SQL injection attacks.
To fix CVE-2008-2455, you should update the e107 BLOG Engine plugin to the latest version that addresses this SQL injection vulnerability.
CVE-2008-2455 allows remote attackers to execute arbitrary SQL commands due to an SQL injection vulnerability.
The affected version of e107 is specifically 2.2 of the e107 BLOG Engine plugin.
Yes, CVE-2008-2455 can be exploited by unauthenticated remote attackers since it affects a publicly accessible script.