Unrated severityNVD Advisory· Published Feb 19, 2009· Updated Apr 23, 2026
CVE-2008-6180
CVE-2008-6180
Description
SQL injection vulnerability in system/nlb_user.class.php in NewLife Blogger 3.0 and earlier, and possibly 3.3.1, allows remote attackers to execute arbitrary SQL commands via the nlb3 cookie.
Affected products
2cpe:2.3:a:newlife_blogger:newlife_blogger:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:newlife_blogger:newlife_blogger:*:*:*:*:*:*:*:*range: <=3.0
- cpe:2.3:a:newlife_blogger:newlife_blogger:3.3.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- www.pepelux.org/exploits/newlife-es.txtnvdExploit
- www.securityfocus.com/bid/31728nvdExploit
- secunia.com/advisories/32214nvdVendor Advisory
- www.securityfocus.com/archive/1/497283/100/0/threadednvd
- www.vupen.com/english/advisories/2008/2797nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/45820nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/45821nvd
- www.exploit-db.com/exploits/6739nvd
News mentions
0No linked articles in our index yet.