7.5
CVSSv2

CVE-2011-5286

Published: 01/01/2015 Updated: 03/01/2015
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in social-slider-2/ajax.php in the Social Slider plugin prior to 7.4.2 for WordPress allows remote malicious users to execute arbitrary SQL commands via the rA array parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

social slider project social slider

Exploits

# Exploit Title: Social Slider <= 565 SQL Injection Vulnerability # Date: 2011-08-05 # Author: Miroslav Stampar (miroslavstampar(at)gmailcom @stamparm) # Software Link: downloadswordpressorg/plugin/social-slider-2zip # Version: 565 (tested) --------------- PoC (POST data) --------------- wwwsitecom/wp-content/plugins/so ...