CVE-2008-6438
E107coders Macguru Blog Engine Plugin - SQL Injection
Title source: ruleDescription
SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows remote attackers to execute arbitrary SQL commands via the uid parameter, a different vector than CVE-2008-2455. NOTE: it was later reported that 2.1.4 is also affected.
Exploits (4)
exploitdb
WORKING POC
VERIFIED
by Virangar Security · perlwebappsphp
https://www.exploit-db.com/exploits/6346
exploitdb
WORKING POC
VERIFIED
by Virangar Security · perlwebappsphp
https://www.exploit-db.com/exploits/6158
exploitdb
WRITEUP
VERIFIED
by Virangar Security · textwebappsphp
https://www.exploit-db.com/exploits/5666
References (9)
Scores
EPSS
0.0236
EPSS Percentile
85.0%
Details
CWE
CWE-89
Status
published
Products (1)
e107coders/macguru_blog_engine_plugin
2.2
Published
Mar 06, 2009
Tracked Since
Feb 18, 2026