SQL injection vulnerability in the Quartz plugin 1.01.1 for WordPress allows remote authenticated users with Contributor privileges to execute arbitrary SQL commands via the quote parameter in an edit action in the quartz/quote_form.php page to wp-admin/edit.php.
References
Link | Resource |
---|---|
http://codevigilant.com/disclosure/wp-plugin-quartz-a1-injection | Exploit |
Configurations
History
No history.
Information
Published : 2014-08-06 19:55
Updated : 2024-02-28 12:20
NVD link : CVE-2014-5185
Mitre link : CVE-2014-5185
CVE.ORG link : CVE-2014-5185
JSON object : View
Products Affected
quartz_plugin_project
- quartz_plugin
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')