CVE-2008-1313
Last modified
CVE-2008-1313 is a vulnerability of currently unknown severity. Multiple SQL injection vulnerabilities in index.php in Bloo 1.00 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) post_id, (2) post_category_id, (3) post_year_month, and (4) static_page_id parameters; and unspecified other vectors.. EPSS estimates a 0.97% chance of exploitation in the next 30 days.
Description
Multiple SQL injection vulnerabilities in index.php in Bloo 1.00 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) post_id, (2) post_category_id, (3) post_year_month, and (4) static_page_id parameters; and unspecified other vectors.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bill Roberts | Bloo | <= 1.0 |
References
- http://secunia.com/advisories/29338Vendor Advisory
- http://secunia.com/advisories/29338Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-1313?
How severe is CVE-2008-1313?
How do I fix CVE-2008-1313?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-1307Heap-based buffer overflow in the KUpdateObj2 Class ActiveX …
- CVE-2008-1308SQL injection vulnerability in the Sudirman Angriawan NukeC3…
- CVE-2008-1309The RealAudioObjects.RealAudio ActiveX control in rmoc3260.d…
- CVE-2008-1310Directory traversal vulnerability in the TFTP server in Pack…
- CVE-2008-1311The TFTP server in PacketTrap pt360 Tool Suite PRO 2.0.3901.…
- CVE-2008-1312Unspecified vulnerability in the TFTP server in PacketTrap N…
- CVE-2008-1314SQL injection vulnerability in the Johannes Hass gaestebuch …
- CVE-2008-1315SQL injection vulnerability in the ZClassifieds module for P…
- CVE-2008-1316SQL injection vulnerability in qtf_ind_search_ov.php in QT-c…
- CVE-2008-1317Unspecified vulnerability in the Inter-Process Communication…
- CVE-2008-1318Unspecified vulnerability in MediaWiki 1.11 before 1.11.2 al…
- CVE-2008-1319Untrusted search path and argument injection vulnerability i…
Are you affected by CVE-2008-1313?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
