1 results (0.003 seconds)

CVSS: 7.2EPSS: 3%CPEs: 2EXPL: 3

12 Mar 2015 — Multiple SQL injection vulnerabilities in the Huge-IT Slider (slider-image) plugin before 2.7.0 for WordPress allow remote administrators to execute arbitrary SQL commands via the removeslide parameter in a popup_posts or edit_cat action in the sliders_huge_it_slider page to wp-admin/admin.php. Múltiples vulnerabilidades de inyección SQL en el plugin Huge-IT Slider (slider-image) versiones anteriores a 2.7.0 para WordPress, permiten a administradores remotos ejecutar comandos SQL arbitrarios por medio del p... • https://packetstorm.news/files/id/130796 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •