📦

macguru_blog_engine_plugin

Vendor: e107coders

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 0 Remote Access
Total CVEs 2 Total Indexed
Avg. EPSS 3.40% Exploit Prob.
Latest CVE CVE-2008-6438 Mar 06

Security Vulnerability Index

Page 1 / 1
7.5 CVSS
CVE-2008-6438
Exploit Found

SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows remote attackers to execute arbitrary SQL commands via the uid parameter, a different vector than CVE-2008-2455. NOTE: it was later reported that 2.1.4 is also affected.

EPSS: 3.40%