CVE-2008-2562
Powerphlogger < 2.2.5 - SQL Injection
Title source: ruleDescription
SQL injection vulnerability in edCss.php in PowerPhlogger 2.2.5 and earlier allows remote authenticated users to execute arbitrary SQL commands via the css_str parameter in an edit action.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by MustLive · textwebappsphp
https://www.exploit-db.com/exploits/5744
References (4)
Scores
EPSS
0.0041
EPSS Percentile
61.1%
Classification
CWE
CWE-89
Status
draft
Affected Products (4)
powerphlogger/powerphlogger
< 2.2.5
powerphlogger/powerphlogger
powerphlogger/powerphlogger
powerphlogger/powerphlogger
Timeline
Published
Jun 06, 2008
Tracked Since
Feb 18, 2026