CVE-2008-0360
BLOG:CMS 4.2.1b - SQL Injection via blogid, user, or field Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-0360. PoCs published by DSecRG.
AI-analyzed exploit summary This advisory details multiple SQL injection and XSS vulnerabilities in Blogcms 4.2.1b, including examples of exploit URLs and payloads. It provides technical descriptions and proof-of-concept attack vectors but does not include executable exploit code.
Description
Multiple SQL injection vulnerabilities in BLOG:CMS 4.2.1b allow remote attackers to execute arbitrary SQL commands via (1) the blogid parameter to index.php, (2) the user parameter to action.php, or (3) the field parameter to admin/plugins/table/index.php.
Exploits (1)
This advisory details multiple SQL injection and XSS vulnerabilities in Blogcms 4.2.1b, including examples of exploit URLs and payloads. It provides technical descriptions and proof-of-concept attack vectors but does not include executable exploit code.