CVE-2014-125049 is a critical SQL injection vulnerability in typcn Blogile, specifically within the getNav function of the server.js file, affecting the blogile_project blogile product. This flaw allows an unauthenticated attacker to execute arbitrary SQL commands by manipulating the 'query' argument. With a CVSS score of 9.8 (Critical), it presents a severe risk with high impact on confidentiality, integrity, and availability, requiring no user interaction or complex attack conditions. Despite its severity, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, and it is noted as affecting an unsupported product.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2014-12-02CPE matchmatch criteria | cpe:2.3:a:blogile_project:blogile:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.