Multiple SQL injection vulnerabilities in CWPPoll.js in WordPress Poll Plugin 34.5 for WordPress allow attackers to execute arbitrary SQL commands via the pollid or poll_id parameter in a viewPollResults or userlogs action.
References
Link Resource
http://www.securityfocus.com/bid/57479 Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/81466 Third Party Advisory VDB Entry
https://www.securityfocus.com/archive/1/525370 Exploit Third Party Advisory VDB Entry
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-02-13T20:19:32

Updated: 2020-02-13T20:19:32

Reserved: 2013-01-19T00:00:00


Link: CVE-2013-1400

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-02-13T21:15:11.443

Modified: 2020-02-19T13:34:43.627


Link: CVE-2013-1400

JSON object: View

cve-icon Redhat Information

No data.

CWE