[Forgot Password]
Login  Register Subscribe

23631

 
 

126951

 
 

99536

 
 

909

 
 

80128

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2018-3811

Date: (C)2018-01-02   (M)2018-01-10 


SQL Injection vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to execute SQL queries in the context of the web server. The saveGoogleAdWords() function in smartgooglecode.php did not use prepared statements and did not sanitize the $_POST["oId"] variable before passing it as input into the SQL query.

CVSS Score: 4.3Access Vector:
Exploit Score: Access Complexity:
Impact Score: Authentication:
 Confidentiality:
 Integrity:
 Availability:





Reference:
EXPLOIT-DB-43420
https://limbenjamin.com/articles/smart-google-code-inserter-auth-bypass.html
https://wordpress.org/plugins/smart-google-code-inserter/#developers
https://wpvulndb.com/vulnerabilities/8988

© 2013 SecPod Technologies