CVE-2009-1481

EXPLOITED IN THE WILD

PuterJam's Blog 3.0.6.170 - SQL Injection via cname Parameter

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2009-1481 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io).

Description

SQL injection vulnerability in action.asp in PuterJam's Blog (PJBlog3) 3.0.6.170 allows remote attackers to execute arbitrary SQL commands via the cname parameter in a checkAlias action, as exploited in the wild in April 2009. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/50082
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/34701
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34897
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/53939

Scores

EPSS 0.0117
EPSS Percentile 64.2%

Details

VulnCheck KEV 2009-04-29
InTheWild.io 2017-08-17
CWE
CWE-89
Status published
Products (1)
pjhome/puterjams_blog 3.0.6.170
Published Apr 29, 2009
Tracked Since Feb 18, 2026