6.5
CVSSv2

CVE-2015-4066

Published: 27/05/2015 Updated: 19/08/2021
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in admin/handlers.php in the GigPress plugin prior to 2.3.9 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) show_artist_id or (2) show_venue_id parameter in an add action in the gigpress.php page to wp-admin/admin.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tri gigpress

Exploits

# Title: SQLi vulnerabilities in WordPress plugin "GigPress" # Author: Adrián M F - adrimf85[at]gmail[dot]com # Date: 2015-05-25 # Vendor Homepage: wordpressorg/plugins/gigpress/ # Active installs: 20,000+ # Vulnerable version: 238 # Fixed version: 239 # CVE: CVE-2015-4066 Vulnerabilities (2) ===================== (1) Authenticat ...
WordPress GigPress plugin version 238 suffers from a remote SQL injection vulnerability ...