Multiple SQL injection vulnerabilities in cs_admin_users.php in the wp-championship plugin 5.8 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) user, (2) isadmin, (3) mail service, (4) mailresceipt, (5) stellv, (6) champtipp, (7) tippgroup, or (8) userid parameter.
References
Link | Resource |
---|---|
http://www.vapid.dhs.org/advisory.php?v=155 | Exploit |
https://wpvulndb.com/vulnerabilities/8221 | Exploit Vendor Advisory |
http://www.vapid.dhs.org/advisory.php?v=155 | Exploit |
https://wpvulndb.com/vulnerabilities/8221 | Exploit Vendor Advisory |
Configurations
History
21 Nov 2024, 02:32
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.vapid.dhs.org/advisory.php?v=155 - Exploit | |
References | () https://wpvulndb.com/vulnerabilities/8221 - Exploit, Vendor Advisory |
Information
Published : 2015-11-02 19:59
Updated : 2024-11-21 02:32
NVD link : CVE-2015-5308
Mitre link : CVE-2015-5308
CVE.ORG link : CVE-2015-5308
JSON object : View
Products Affected
wp-championship_project
- wp-championship
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')