All-in-One Event Calendar Plugin Multiple Cross Site Scripting and SQL Injection Vulnerabilities
BID:61765
Info
All-in-One Event Calendar Plugin Multiple Cross Site Scripting and SQL Injection Vulnerabilities
| Bugtraq ID: | 61765 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 24 2013 12:00AM |
| Updated: | Jul 24 2013 12:00AM |
| Credit: | Christian Mehlmauer |
| Vulnerable: |
The Seed Studio All-in-One Event Calendar Plugin 1.9 |
| Not Vulnerable: |
The Seed Studio All-in-One Event Calendar Plugin 1.10 |
Discussion
All-in-One Event Calendar Plugin Multiple Cross Site Scripting and SQL Injection Vulnerabilities
All-in-One Event Calendar plugin for WordPress is prone to multiple cross-site scripting and SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input.
Attackers can exploit these issues to execute arbitrary code in the context of the browser, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database; other attacks are also possible.
All-in-One Event Calendar 1.9 is vulnerable; other versions may also be affected.
All-in-One Event Calendar plugin for WordPress is prone to multiple cross-site scripting and SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input.
Attackers can exploit these issues to execute arbitrary code in the context of the browser, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database; other attacks are also possible.
All-in-One Event Calendar 1.9 is vulnerable; other versions may also be affected.
Exploit / POC
All-in-One Event Calendar Plugin Multiple Cross Site Scripting and SQL Injection Vulnerabilities
An attacker can use a browser to exploit these issues. An attacker must trick a victim into following a malicious URI to exploit cross-site scripting issues.
An attacker can use a browser to exploit these issues. An attacker must trick a victim into following a malicious URI to exploit cross-site scripting issues.
Solution / Fix
All-in-One Event Calendar Plugin Multiple Cross Site Scripting and SQL Injection Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
All-in-One Event Calendar Plugin Multiple Cross Site Scripting and SQL Injection Vulnerabilities
References:
References:
- All-in-One Event Calendar Changelog (The Seed Studio)
- All-in-One Event Calendar Product Page (The Seed Studio)