CVE-2013-1401 – WordPress Poll <= 34.05 - SQL Injection
https://notcve.org/view.php?id=CVE-2013-1401
Multiple security bypass vulnerabilities in the editAnswer, deleteAnswer, addAnswer, and deletePoll functions in WordPress Poll Plugin 34.5 for WordPress allow a remote attacker to add, edit, and delete an answer and delete a poll. Múltiples vulnerabilidades de seguridad en las funciones editAnswer, deleteAnswer, addAnswer y deletePoll en WordPress Poll Plugin versión 34.5 para WordPress, permiten a un atacante remoto agregar, editar y eliminar una respuesta y eliminar una encuesta. Multiple security bypass vulnerabilities in the editAnswer, deleteAnswer, addAnswer, and deletePoll functions in WordPress Poll Plugin 34.05 for WordPress allow a remote attacker to add, edit, and delete an answer and delete a poll. Cardoza WordPress Poll plugin version 34.05 suffers from multiple remote SQL injection vulnerabilities. • http://www.securityfocus.com/bid/57479 https://exchange.xforce.ibmcloud.com/vulnerabilities/81467 https://www.securityfocus.com/archive/1/525370 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2013-1400 – WordPress Poll < 34.06 - SQL Injection
https://notcve.org/view.php?id=CVE-2013-1400
Multiple SQL injection vulnerabilities in CWPPoll.js in WordPress Poll Plugin 34.5 for WordPress allow attackers to execute arbitrary SQL commands via the pollid or poll_id parameter in a viewPollResults or userlogs action. Múltiples vulnerabilidades de inyección SQL en el archivo CWPPoll.js en WordPress Poll Plugin versión 34.5 para WordPress, permiten a atacantes ejecutar comandos SQL arbitrarios por medio del parámetro pollid o poll_id en una acción viewPollResults o userlogs. Cardoza WordPress Poll plugin version 34.05 suffers from multiple remote SQL injection vulnerabilities. • http://www.securityfocus.com/bid/57479 https://exchange.xforce.ibmcloud.com/vulnerabilities/81466 https://www.securityfocus.com/archive/1/525370 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •