7.5
CVSSv2

CVE-2011-1047

Published: 21/02/2011 Updated: 09/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in VastHTML Forum Server (aka ForumPress) plugin 1.6.1 and 1.6.5 for WordPress allow remote malicious users to execute arbitrary SQL commands via the (1) search_max parameter in a search action to index.php, which is not properly handled by wpf.class.php, (2) id parameter in an editpost action to index.php, which is not properly handled by wpf-post.php, or (3) topic parameter to feed.php.

Vulnerable Product Search on Vulmon Subscribe to Product

vasthtml forum_server 1.6.5

vasthtml forum_server 1.6.1

Exploits

Vulnerability ID: HTB22851 Reference: wwwhtbridgech/advisory/sql_injection_in_wp_forum_server_wordpre ss_plugin_1html Product: WP Forum Server wordpress plugin Vendor: VastHTML Vulnerable Version: 165 Vendor Notification: 10 February 2011 Vulnerability Type: SQL Injection Risk level: High Credit: High-Tech Bridge SA - Ethical Hacking &a ...