Multiple SQL injection vulnerabilities in cs_admin_users.php in the wp-championship plugin 5.8 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) user, (2) isadmin, (3) mail service, (4) mailresceipt, (5) stellv, (6) champtipp, (7) tippgroup, or (8) userid parameter.
References
Link | Resource |
---|---|
http://www.vapid.dhs.org/advisory.php?v=155 | Exploit |
https://wpvulndb.com/vulnerabilities/8221 | Exploit Vendor Advisory |
Configurations
Information
Published : 2015-11-02 11:59
Updated : 2015-11-03 18:47
NVD link : CVE-2015-5308
Mitre link : CVE-2015-5308
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
wp-championship_project
- wp-championship