WordPress Community Events plug-in multiple SQL Injection Vulnerabilities (CVE-2015-3313)
WordPress Community Events plug-in multiple SQL Injection Vulnerabilities (CVE-2015-3313)
Release date:
Updated on:
Affected Systems:
WordPress Community Events 1.3.5
Description:
Bugtraq id: 74234
CVE (CAN) ID: CVE-2015-3313
WordPress Community Events plugin event plan timeline plugin.
WordPress Community Events 1.3.5 has the SQL injection vulnerability. Attackers can exploit this vulnerability to obtain sensitive information.
<* Source: Hannes Trunde
*>
Test method:
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Hannes Trunde () provides the following test methods:
Http://www.site.com /? Page_id = 2 & eventyear = 2015 AND 1 = 0) -- & dateset = on & eventday = 1
Suggestion:
Vendor patch:
WordPress
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://wordpress.org/plugins/community-events/
Reference: https://www.exploit-db.com/exploits/36805/
This article permanently updates the link address: