7.5
CVSSv2

CVE-2012-6625

Published: 16/01/2014 Updated: 08/12/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in fs-admin/fs-admin.php in the ForumPress WP Forum Server plugin prior to 1.7.4 for WordPress allows remote malicious users to execute arbitrary SQL commands via the groupid parameter in an editgroup action.

Vulnerable Product Search on Vulmon Subscribe to Product

vasthtml forumpress 1.2

vasthtml forumpress 1.3

vasthtml forumpress 1.5.1

vasthtml forumpress 1.6.4

vasthtml forumpress 1.6.5

vasthtml forumpress 1.7.2

vasthtml forumpress 1.7.3

vasthtml forumpress 1.5.2

vasthtml forumpress 1.6.8

vasthtml forumpress 1.6.9

vasthtml forumpress 1.4

vasthtml forumpress 1.5

vasthtml forumpress 1.6.6

vasthtml forumpress 1.6.7

vasthtml forumpress

vasthtml forumpress 1.0

vasthtml forumpress 1.1

vasthtml forumpress 1.6

vasthtml forumpress 1.6.2

vasthtml forumpress 1.6.3

vasthtml forumpress 1.7

vasthtml forumpress 1.7.1

Exploits

# Exploit Title: WordPress WP Forum Server plugin <= 17 SQL Injection Vulnerability # Date: 2011-09-07 # Author: Miroslav Stampar (miroslavstampar(at)gmailcom @stamparm) # Software Link: downloadswordpressorg/plugin/forum-serverzip # Version: 17 (tested) --------------- PoC (POST data) --------------- wwwsitecom/wp-conten ...