CVE-2012-6625

SQL injection vulnerability in fs-admin/fs-admin.php in the ForumPress WP Forum Server plugin before 1.7.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the groupid parameter in an editgroup action.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:vasthtml:forumpress:*:-:-:*:-:wordpress:*:*
cpe:2.3:a:vasthtml:forumpress:1.0:-:-:*:-:wordpress:*:*
cpe:2.3:a:vasthtml:forumpress:1.1:-:-:*:-:wordpress:*:*
cpe:2.3:a:vasthtml:forumpress:1.2:-:-:*:-:wordpress:*:*
cpe:2.3:a:vasthtml:forumpress:1.3:-:-:*:-:wordpress:*:*
cpe:2.3:a:vasthtml:forumpress:1.4:-:-:*:-:wordpress:*:*
cpe:2.3:a:vasthtml:forumpress:1.5:-:-:*:-:wordpress:*:*
cpe:2.3:a:vasthtml:forumpress:1.5.1:-:-:*:-:wordpress:*:*
cpe:2.3:a:vasthtml:forumpress:1.5.2:-:-:*:-:wordpress:*:*
cpe:2.3:a:vasthtml:forumpress:1.6:-:-:*:-:wordpress:*:*
cpe:2.3:a:vasthtml:forumpress:1.6.2:-:-:*:-:wordpress:*:*
cpe:2.3:a:vasthtml:forumpress:1.6.3:-:-:*:-:wordpress:*:*
cpe:2.3:a:vasthtml:forumpress:1.6.4:-:-:*:-:wordpress:*:*
cpe:2.3:a:vasthtml:forumpress:1.6.5:-:-:*:-:wordpress:*:*
cpe:2.3:a:vasthtml:forumpress:1.6.6:-:-:*:-:wordpress:*:*
cpe:2.3:a:vasthtml:forumpress:1.6.7:-:-:*:-:wordpress:*:*
cpe:2.3:a:vasthtml:forumpress:1.6.8:-:-:*:-:wordpress:*:*
cpe:2.3:a:vasthtml:forumpress:1.6.9:-:-:*:-:wordpress:*:*
cpe:2.3:a:vasthtml:forumpress:1.7:-:-:*:-:wordpress:*:*
cpe:2.3:a:vasthtml:forumpress:1.7.1:-:-:*:-:wordpress:*:*
cpe:2.3:a:vasthtml:forumpress:1.7.2:-:-:*:-:wordpress:*:*
cpe:2.3:a:vasthtml:forumpress:1.7.3:-:-:*:-:wordpress:*:*

History

21 Nov 2024, 01:46

Type Values Removed Values Added
References () http://packetstormsecurity.org/files/112703/WordPress-WP-Forum-Server-1.7.3-SQL-Injection-Cross-Site-Scripting.html - () http://packetstormsecurity.org/files/112703/WordPress-WP-Forum-Server-1.7.3-SQL-Injection-Cross-Site-Scripting.html -
References () http://wordpress.org/extend/plugins/forum-server/changelog/ - Patch, Vendor Advisory () http://wordpress.org/extend/plugins/forum-server/changelog/ - Patch, Vendor Advisory
References () http://www.securityfocus.com/bid/53530 - () http://www.securityfocus.com/bid/53530 -
References () https://plugins.trac.wordpress.org/changeset/532918 - () https://plugins.trac.wordpress.org/changeset/532918 -

Information

Published : 2014-01-16 21:55

Updated : 2024-11-21 01:46


NVD link : CVE-2012-6625

Mitre link : CVE-2012-6625

CVE.ORG link : CVE-2012-6625


JSON object : View

Products Affected

vasthtml

  • forumpress
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')