WordPress Participants Database Plugin SQL Injection and Access Bypass Vulnerabilities
BID:67769
Info
WordPress Participants Database Plugin SQL Injection and Access Bypass Vulnerabilities
| Bugtraq ID: | 67769 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-3961 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 02 2014 12:00AM |
| Updated: | Jun 25 2014 04:35PM |
| Credit: | Yarubo Research Team |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
WordPress Participants Database Plugin SQL Injection and Access Bypass Vulnerabilities
The Participants Database plugin for WordPress is prone to an SQL-injection vulnerability and an access-bypass vulnerability.
Exploiting these issues could allow an attacker to bypass certain security restrictions and perform unauthorized actions, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Participants Database 1.5.4.8 is vulnerable; other versions may also be affected.
The Participants Database plugin for WordPress is prone to an SQL-injection vulnerability and an access-bypass vulnerability.
Exploiting these issues could allow an attacker to bypass certain security restrictions and perform unauthorized actions, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Participants Database 1.5.4.8 is vulnerable; other versions may also be affected.
Exploit / POC
WordPress Participants Database Plugin SQL Injection and Access Bypass Vulnerabilities
An attacker can exploit these issues using a browser.
An attacker can exploit these issues using a browser.
Solution / Fix
WordPress Participants Database Plugin SQL Injection and Access Bypass Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
WordPress Participants Database Plugin SQL Injection and Access Bypass Vulnerabilities
References:
References: