CVE-2008-4072
Phsdev Phsblog - SQL Injection
Title source: ruleDescription
Multiple SQL injection vulnerabilities in index.php in phsBlog 0.2 allow remote attackers to execute arbitrary SQL commands via (1) the sid parameter in a pickup action or (2) the sql_cid parameter, different vectors than CVE-2008-3588.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Khashayar Fereidani · perlwebappsphp
https://www.exploit-db.com/exploits/6431
References (6)
Scores
EPSS
0.0111
EPSS Percentile
78.2%
Details
CWE
CWE-89
Status
published
Products (1)
phsdev/phsblog
0.2
Published
Sep 15, 2008
Tracked Since
Feb 18, 2026