SQL injection vulnerability in the Quartz plugin 1.01.1 for WordPress allows remote authenticated users with Contributor privileges to execute arbitrary SQL commands via the quote parameter in an edit action in the quartz/quote_form.php page to wp-admin/edit.php.
References
Link | Resource |
---|---|
http://codevigilant.com/disclosure/wp-plugin-quartz-a1-injection | Exploit |
Configurations
Information
Published : 2014-08-06 12:55
Updated : 2014-08-07 06:14
NVD link : CVE-2014-5185
Mitre link : CVE-2014-5185
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
quartz_plugin_project
- quartz_plugin