CVE-2008-6438: SQL Injection
Published Mar 6, 2009
·Updated
SQL injection vulnerability in macgurublogmenu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows remote attackers to execute arbitrary SQL commands via the uid parameter, a different vector than CVE-2008-2455. NOTE: it was later reported that 2.1.4 is also affected.
Affected Software
4 affected components
E107coders Macguru Blog Engine Plugin=2.2
e107 e107
All of the following
E107coders Macguru Blog Engine Plugin=2.2
e107 e107
Event History
Mar 6, 2009
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
06:30 PM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·06:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-6438?
CVE-2008-6438 has a moderate severity rating due to the potential for SQL injection attacks.
2
How do I fix CVE-2008-6438?
To fix CVE-2008-6438, upgrade the MacGuru BLOG Engine plugin to the latest version that addresses this vulnerability.
3
What is affected by CVE-2008-6438?
CVE-2008-6438 affects the MacGuru BLOG Engine plugin version 2.2 for e107.
4
Can CVE-2008-6438 be exploited remotely?
Yes, CVE-2008-6438 can be exploited remotely by executing arbitrary SQL commands.
5
Was an earlier version also affected by CVE-2008-6438?
Yes, it was reported that version 2.1.4 of the MacGuru BLOG Engine plugin is also affected.