7.5
CVSSv2

CVE-2014-3961

Published: 04/06/2014 Updated: 14/02/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the Export CSV page in the Participants Database plugin prior to 1.5.4.9 for WordPress allows remote malicious users to execute arbitrary SQL commands via the query parameter in an "output CSV" action to pdb-signup/.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

xnau participants database

xnau participants database 1.5.4.7

xnau participants database 1.5.4.2

xnau participants database 1.5.4.4

xnau participants database 1.5.4.3

xnau participants database 1.5.4.5

xnau participants database 1.5.4

xnau participants database 1.5.4.6

xnau participants database 1.5.4.1

Exploits

Yarubo #1: Arbitrary SQL Execution in Participants Database for Wordpress ========================================================================= Program: Participants Database <= 1548 Severity: Unauthenticated attacker can fully compromise the Wordpress installation Permalink: wwwyarubocom/advisories/1 — Info — Participants ...