Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-1408

Опубликовано: 24 мар. 2014
Источник: nvd
CVSS2: 6.5
EPSS Низкий

Описание

Multiple SQL injection vulnerabilities in the Wysija Newsletters plugin before 2.2.1 for WordPress allow remote authenticated administrators to execute arbitrary SQL commands via the (1) search or (2) orderby parameter to wp-admin/admin.php. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to execute arbitrary SQL commands.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:wysija_newsletters_project:wysija_newsletters:*:*:*:*:*:wordpress:*:*
Версия до 2.2 (включая)
cpe:2.3:a:wysija_newsletters_project:wysija_newsletters:2.0:*:*:*:*:wordpress:*:*
cpe:2.3:a:wysija_newsletters_project:wysija_newsletters:2.0.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:wysija_newsletters_project:wysija_newsletters:2.0.2:*:*:*:*:wordpress:*:*
cpe:2.3:a:wysija_newsletters_project:wysija_newsletters:2.0.3:*:*:*:*:wordpress:*:*
cpe:2.3:a:wysija_newsletters_project:wysija_newsletters:2.0.4:*:*:*:*:wordpress:*:*
cpe:2.3:a:wysija_newsletters_project:wysija_newsletters:2.0.5:*:*:*:*:wordpress:*:*
cpe:2.3:a:wysija_newsletters_project:wysija_newsletters:2.0.6:*:*:*:*:wordpress:*:*
cpe:2.3:a:wysija_newsletters_project:wysija_newsletters:2.0.7:*:*:*:*:wordpress:*:*
cpe:2.3:a:wysija_newsletters_project:wysija_newsletters:2.0.8:*:*:*:*:wordpress:*:*
cpe:2.3:a:wysija_newsletters_project:wysija_newsletters:2.0.9:*:*:*:*:wordpress:*:*
cpe:2.3:a:wysija_newsletters_project:wysija_newsletters:2.0.9.5:*:*:*:*:wordpress:*:*
cpe:2.3:a:wysija_newsletters_project:wysija_newsletters:2.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:wysija_newsletters_project:wysija_newsletters:2.1.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:wysija_newsletters_project:wysija_newsletters:2.1.2:*:*:*:*:wordpress:*:*
cpe:2.3:a:wysija_newsletters_project:wysija_newsletters:2.1.3:*:*:*:*:wordpress:*:*
cpe:2.3:a:wysija_newsletters_project:wysija_newsletters:2.1.4:*:*:*:*:wordpress:*:*
cpe:2.3:a:wysija_newsletters_project:wysija_newsletters:2.1.5:*:*:*:*:wordpress:*:*
cpe:2.3:a:wysija_newsletters_project:wysija_newsletters:2.1.6:*:*:*:*:wordpress:*:*
cpe:2.3:a:wysija_newsletters_project:wysija_newsletters:2.1.7:*:*:*:*:wordpress:*:*
cpe:2.3:a:wysija_newsletters_project:wysija_newsletters:2.1.8:*:*:*:*:wordpress:*:*
cpe:2.3:a:wysija_newsletters_project:wysija_newsletters:2.1.9:*:*:*:*:wordpress:*:*

EPSS

Процентиль: 85%
0.02578
Низкий

6.5 Medium

CVSS2

Дефекты

CWE-89

Связанные уязвимости

github
больше 3 лет назад

Multiple SQL injection vulnerabilities in the Wysija Newsletters plugin before 2.2.1 for WordPress allow remote authenticated administrators to execute arbitrary SQL commands via the (1) search or (2) orderby parameter to wp-admin/admin.php. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to execute arbitrary SQL commands.

EPSS

Процентиль: 85%
0.02578
Низкий

6.5 Medium

CVSS2

Дефекты

CWE-89