CVE-2011-1047
WP Forum Server <= 1.6.5 - SQL Injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Multiple SQL injection vulnerabilities in VastHTML Forum Server (aka ForumPress) plugin 1.6.1 and 1.6.5 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) search_max parameter in a search action to index.php, which is not properly handled by wpf.class.php, (2) id parameter in an editpost action to index.php, which is not properly handled by wpf-post.php, or (3) topic parameter to feed.php.
Múltiples vulnerabilidades de inyección SQL en el plugin Forum Server (también se conoce como ForumPress) versiones 1.6.1 y 1.6.5 de VastHTML para WordPress, permiten a los atacantes remotos ejecutar comandos SQL arbitrarios por medio del (1) parámetro search_max en una acción search en el archivo index.php, que no es manejado apropiadamente por el archivo wpf.class.php, (2) parámetro id en una acción editpost en archivo index.php, que no es manejado apropiadamente por archivo wpf-post.php, o (3) topic a feed.php.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2011-02-21 CVE Reserved
- 2011-02-21 CVE Published
- 2011-02-24 First Exploit
- 2023-03-12 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://osvdb.org/70993 | Vdb Entry | |
http://osvdb.org/70994 | Vdb Entry | |
http://www.htbridge.ch/advisory/sql_injection_in_wp_forum_server_wordpress_plugin.html | X_refsource_misc | |
http://www.htbridge.ch/advisory/sql_injection_in_wp_forum_server_wordpress_plugin_1.html | X_refsource_misc | |
http://www.htbridge.ch/advisory/sql_injection_in_wp_forum_server_wordpress_plugin_2.html | X_refsource_misc | |
http://www.securityfocus.com/archive/1/516400/100/0/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/516402/100/0/threaded | Mailing List |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/16235 | 2011-02-24 | |
http://securityreason.com/securityalert/8099 | 2024-08-06 | |
http://www.securityfocus.com/bid/46362 | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/43306 | 2018-10-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Vasthtml Search vendor "Vasthtml" | Forum Server Search vendor "Vasthtml" for product "Forum Server" | 1.6.1 Search vendor "Vasthtml" for product "Forum Server" and version "1.6.1" | - |
Affected
| in | Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | * | - |
Safe
|
Vasthtml Search vendor "Vasthtml" | Forum Server Search vendor "Vasthtml" for product "Forum Server" | 1.6.5 Search vendor "Vasthtml" for product "Forum Server" and version "1.6.5" | - |
Affected
| in | Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | * | - |
Safe
|