CVE-2008-6077

LoudBlog <0.8.0a - SQL Injection

Title source: llm

Description

SQL injection vulnerability in loudblog/ajax.php in LoudBlog 0.8.0a and earlier allows remote authenticated users to execute arbitrary SQL commands via the colpick parameter in a singleread action.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Xianur0 · perlwebappsphp
https://www.exploit-db.com/exploits/6808

Scores

EPSS 0.0041
EPSS Percentile 61.5%

Details

CWE
CWE-89
Status published
Products (5)
loudblog/loudblog 0.5
loudblog/loudblog 0.6
loudblog/loudblog 0.7
loudblog/loudblog 0.8.0
loudblog/loudblog < 0.8.0a
Published Feb 06, 2009
Tracked Since Feb 18, 2026