CVE-2008-0682

UnknownEPSS 2.85%

Last modified

CVE-2008-0682 is a vulnerability of currently unknown severity. SQL injection vulnerability in wordspew-rss.php in the Wordspew plugin before 3.72 for Wordpress allows remote attackers to execute arbitrary SQL commands via the id parameter.. EPSS estimates a 2.85% chance of exploitation in the next 30 days.

Description

SQL injection vulnerability in wordspew-rss.php in the Wordspew plugin before 3.72 for Wordpress allows remote attackers to execute arbitrary SQL commands via the id parameter.

Metrics

EPSS Probability
2.85%

84.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
WordpressWordspew<= 3.71
WordpressWordspew1.6
WordpressWordspew1.7
WordpressWordspew1.8
WordpressWordspew2.0
WordpressWordspew2.1
WordpressWordspew2.2
WordpressWordspew2.3
WordpressWordspew2.5
WordpressWordspew2.6
WordpressWordspew2.7
WordpressWordspew2.8
WordpressWordspew2.9
WordpressWordspew2.31
WordpressWordspew2.32
WordpressWordspew2.85
WordpressWordspew2.91
WordpressWordspew2.92
WordpressWordspew2.93
WordpressWordspew2.94
WordpressWordspew2.95
WordpressWordspew3.0
WordpressWordspew3.01
WordpressWordspew3.1
WordpressWordspew3.2
WordpressWordspew3.02
WordpressWordspew3.3
WordpressWordspew3.6
WordpressWordspew3.7
WordpressWordspew3.15
WordpressWordspew3.16
WordpressWordspew3.021
WordpressWordspew3.022
WordpressWordspew3.31
WordpressWordspew3.32
WordpressWordspew3.33
WordpressWordspew3.34
WordpressWordspew3.51
WordpressWordspew3.52

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2008-0682?
SQL injection vulnerability in wordspew-rss.php in the Wordspew plugin before 3.72 for Wordpress allows remote attackers to execute arbitrary SQL commands via the id parameter.
How severe is CVE-2008-0682?
Severity scoring for CVE-2008-0682 is pending analysis. The EPSS model estimates a 2.85% probability of exploitation in the next 30 days.
How do I fix CVE-2008-0682?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2008-0682?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST