CVE-2014-3961
N/A
N/A
Summary
SQL injection vulnerability in the Export CSV page in the Participants Database plugin before 1.5.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the query parameter in an "output CSV" action to pdb-signup/.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://packetstormsecurity.com/files/126878/WordPress-Participants-Database-1.5.4.8-SQL-Injection.html
- https://www.yarubo.com/advisories/1
- http://www.exploit-db.com/exploits/33613
- https://wordpress.org/plugins/participants-database/changelog
- http://seclists.org/fulldisclosure/2014/Jun/0
- http://osvdb.org/show/osvdb/107626
- http://www.securityfocus.com/bid/67769
References
- http://packetstormsecurity.com/files/126878/WordPress-Participants-Database-1.5.4.8-SQL-Injection.html
- https://www.yarubo.com/advisories/1
- http://www.exploit-db.com/exploits/33613
- https://wordpress.org/plugins/participants-database/changelog
- http://seclists.org/fulldisclosure/2014/Jun/0
- http://osvdb.org/show/osvdb/107626
- http://www.securityfocus.com/bid/67769
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.