
CVE-2012-1067 – WP-RecentComments <= 2.0.7 - SQL Injection
https://notcve.org/view.php?id=CVE-2012-1067
22 Sep 2011 — SQL injection vulnerability in the WP-RecentComments plugin 2.0.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter in an rc-content action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Vulnerabilidad de inyección SQL en el complemento WP-RecentComments v2.0.7 para WordPress, permite a atacantes remotos ejecutar comandos SQL de su elección a través del parámetro id en una acción rc-c... • http://osvdb.org/78820 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2012-1068 – WP-RecentComments <= 2.0.6 - Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2012-1068
22 Sep 2011 — Cross-site scripting (XSS) vulnerability in the rc_ajax function in core.php in the WP-RecentComments plugin before 2.0.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter, related to AJAX paging. Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en la función rc_ajax en core.php en el complemento WP-RecentComments v2.0.7 para WordPress, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro... • http://plugins.trac.wordpress.org/changeset/416723/wp-recentcomments/trunk/core.php?old=316325&old_path=wp-recentcomments%2Ftrunk%2Fcore.php • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •