CVE-2008-6438

E107coders Macguru Blog Engine Plugin - SQL Injection

Title source: rule

Description

SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows remote attackers to execute arbitrary SQL commands via the uid parameter, a different vector than CVE-2008-2455. NOTE: it was later reported that 2.1.4 is also affected.

Exploits (4)

exploitdb WORKING POC VERIFIED
by ZoRLu · textwebappsphp
https://www.exploit-db.com/exploits/6856
exploitdb WORKING POC VERIFIED
by Virangar Security · perlwebappsphp
https://www.exploit-db.com/exploits/6346
exploitdb WORKING POC VERIFIED
by Virangar Security · perlwebappsphp
https://www.exploit-db.com/exploits/6158
exploitdb WRITEUP VERIFIED
by Virangar Security · textwebappsphp
https://www.exploit-db.com/exploits/5666

Scores

EPSS 0.0236
EPSS Percentile 85.0%

Details

CWE
CWE-89
Status published
Products (1)
e107coders/macguru_blog_engine_plugin 2.2
Published Mar 06, 2009
Tracked Since Feb 18, 2026