7.5
CVSSv2

CVE-2015-2824

Published: 06/04/2015 Updated: 09/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in the Simple Ads Manager plugin prior to 2.7.97 for WordPress allow remote malicious users to execute arbitrary SQL commands via a (1) hits[][] parameter in a sam_hits action to sam-ajax.php; the (2) cstr parameter in a load_posts action to sam-ajax-admin.php; the (3) searchTerm parameter in a load_combo_data action to sam-ajax-admin.php; or the (4) subscriber, (5) contributor, (6) author, (7) editor, (8) admin, or (9) sadmin parameter in a load_users action to sam-ajax-admin.php.

Vulnerable Product Search on Vulmon Subscribe to Product

simple ads manager project simple ads manager 2.5.96

simple ads manager project simple ads manager 2.5.94

Exploits

#Vulnerability title: Wordpress plugin Simple Ads Manager - SQL Injection #Product: Wordpress plugin Simple Ads Manager #Vendor: profileswordpressorg/minimus/ #Affected version: Simple Ads Manager 2594 and 2596 #Download link: wordpressorg/plugins/simple-ads-manager/ #CVE ID: CVE-2015-2824 #Author: Le Hong Minh (minhhle@ita ...
WordPress Simple Ads Manager plugin versions 2594 and 2596 suffer from multiple remote SQL injection vulnerabilities ...