blogator-script records
2 published records for vendor blogator-script.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-255 Credentials Management Errors1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
28Monitor | CVE-2008-1760Proof of concept | Multiple PHP remote file inclusion vulnerabilities in Blogator-script before 1.01 allow remote attackers to execute arbitrary PHP code via ablogator-script · blogator-script · CWE-94 | Medium6.8 | — | 2.3% | Apr 12, 2008 |
26Monitor | CVE-2008-6473Proof of concept | _blogadata/include/init_pass2.php in Blogator-script 0.95 allows remote attackers to change the password for arbitrary users via a modified blogator-script · blogator-script · CWE-255 | Medium6.4 | — | 2.3% | Mar 16, 2009 |
- CVE-2008-176028Monitor
Multiple PHP remote file inclusion vulnerabilities in Blogator-script before 1.01 allow remote attackers to execute arbitrary PHP code via a
MediumCVSS 6.8Proof of conceptEPSS 2%blogator-script · blogator-scriptApr 12, 2008
- CVE-2008-647326Monitor
_blogadata/include/init_pass2.php in Blogator-script 0.95 allows remote attackers to change the password for arbitrary users via a modified
MediumCVSS 6.4Proof of conceptEPSS 2%blogator-script · blogator-scriptMar 16, 2009