7.5
CVSSv2

CVE-2015-6522

Published: 19/08/2015 Updated: 09/12/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the WP Symposium plugin prior to 15.8 for WordPress allows remote malicious users to execute arbitrary SQL commands via the size parameter to get_album_item.php.

Vulnerable Product Search on Vulmon Subscribe to Product

wpsymposium wp symposium

Exploits

# Exploit Title: Wordpress Plugin wp-symposium Unauthenticated SQL Injection Vulnerability # Date: 2015-07-30 # Exploit Author: PizzaHatHacker # Vendor Homepage: wwwwpsymposiumcom/ # Version: ? <= version <= 1551 # Contact: PizzaHatHacker[a]gmail[]com # Tested on: Apache / WordPress 423 / wp-symposium 1551 # CVE: # Category: ...