7.5
CVSSv2

CVE-2009-2383

Published: 08/07/2009 Updated: 19/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in BTE_RW_webajax.php in the Related Sites plugin 2.1 for WordPress allows remote malicious users to execute arbitrary SQL commands via the guid parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

blogtrafficexchange related-sites 2.1

Exploits

WordPress Plugin Related Sites 21 BlindSQLinj Vuln wordpressorg/extend/plugins/related-sites/ /wp-content/plugins/related-sites/BTE_RW_webajaxphp eLwaux(c) 30052009, uascorgua SQL-Inj 27: $guid = $_POST['guid']; 28: $click = $_POST['click']; 31: $ref = $_SERVER["HTTP_REFERER"]; 40: if ($guid!="" && $click!="" && ...