SQL injection vulnerability in mycategoryorder.php in the My Category Order plugin 2.8 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the parentID parameter in an act_OrderCategories action to wp-admin/post-new.php.
References
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2010-03-26 13:30
Updated : 2017-09-18 18:30
NVD link : CVE-2009-4748
Mitre link : CVE-2009-4748
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
wordpress
- wordpress
andrew_charlton
- my_category_order