7.5
CVSSv2

CVE-2015-7235

Published: 17/09/2015 Updated: 22/12/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in dex_reservations.php in the CP Reservation Calendar plugin prior to 1.1.7 for WordPress allow remote malicious users to execute arbitrary SQL commands via the (1) id parameter in a dex_reservations_calendar_load2 action or (2) dex_item parameter in a dex_reservations_check_posted_data action in a request to the default URI.

Vulnerable Product Search on Vulmon Subscribe to Product

cp reservation calender project cp reservation calender

Exploits

# Exploit Title: WordPress: cp-reservation-calendar 116 SQLi injection] # Date: 2015-09-15 # Google Dork: Index of /wp-content/plugins/cp-reservation-calendar/ # Exploit Author: Joaquin Ramirez Martinez [ i0akiN SEC-LABORATORY ] # Software Link: downloadswordpressorg/plugin/cp-reservation-calendarzip # Version: 116 # OWASP Top10: A1 ...