CVE-2014-3961
Participants Database < 1.5.4.9 - SQL Injection
Severity Score
9.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
5
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
SQL injection vulnerability in the Export CSV page in the Participants Database plugin before 1.5.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the query parameter in an "output CSV" action to pdb-signup/.
Vulnerabilidad de inyección SQL en la página Export CSV en el plugin Participants Database anterior a 1.5.4.9 para WordPress permite a atacantes remotos ejecutar comandos SQL arbitrarios a través del parámetro query en una acción 'output CSV' hacia pdb-signup/.
*Credits:
Yarubo Research Team
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2014-06-02 CVE Published
- 2014-06-02 First Exploit
- 2014-06-04 CVE Reserved
- 2024-09-16 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://osvdb.org/show/osvdb/107626 | Vdb Entry | |
http://www.securityfocus.com/bid/67769 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/33613 | 2014-06-02 | |
http://packetstormsecurity.com/files/126878/WordPress-Participants-Database-1.5.4.8-SQL-Injection.html | 2024-09-16 | |
http://seclists.org/fulldisclosure/2014/Jun/0 | 2024-09-16 | |
http://www.exploit-db.com/exploits/33613 | 2024-09-16 | |
https://www.yarubo.com/advisories/1 | 2024-09-16 |
URL | Date | SRC |
---|---|---|
https://wordpress.org/plugins/participants-database/changelog | 2024-02-14 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Xnau Search vendor "Xnau" | Participants Database Search vendor "Xnau" for product "Participants Database" | <= 1.5.4.8 Search vendor "Xnau" for product "Participants Database" and version " <= 1.5.4.8" | wordpress |
Affected
| ||||||
Xnau Search vendor "Xnau" | Participants Database Search vendor "Xnau" for product "Participants Database" | 1.5.4 Search vendor "Xnau" for product "Participants Database" and version "1.5.4" | wordpress |
Affected
| ||||||
Xnau Search vendor "Xnau" | Participants Database Search vendor "Xnau" for product "Participants Database" | 1.5.4.1 Search vendor "Xnau" for product "Participants Database" and version "1.5.4.1" | wordpress |
Affected
| ||||||
Xnau Search vendor "Xnau" | Participants Database Search vendor "Xnau" for product "Participants Database" | 1.5.4.2 Search vendor "Xnau" for product "Participants Database" and version "1.5.4.2" | wordpress |
Affected
| ||||||
Xnau Search vendor "Xnau" | Participants Database Search vendor "Xnau" for product "Participants Database" | 1.5.4.3 Search vendor "Xnau" for product "Participants Database" and version "1.5.4.3" | wordpress |
Affected
| ||||||
Xnau Search vendor "Xnau" | Participants Database Search vendor "Xnau" for product "Participants Database" | 1.5.4.4 Search vendor "Xnau" for product "Participants Database" and version "1.5.4.4" | wordpress |
Affected
| ||||||
Xnau Search vendor "Xnau" | Participants Database Search vendor "Xnau" for product "Participants Database" | 1.5.4.5 Search vendor "Xnau" for product "Participants Database" and version "1.5.4.5" | wordpress |
Affected
| ||||||
Xnau Search vendor "Xnau" | Participants Database Search vendor "Xnau" for product "Participants Database" | 1.5.4.6 Search vendor "Xnau" for product "Participants Database" and version "1.5.4.6" | wordpress |
Affected
| ||||||
Xnau Search vendor "Xnau" | Participants Database Search vendor "Xnau" for product "Participants Database" | 1.5.4.7 Search vendor "Xnau" for product "Participants Database" and version "1.5.4.7" | wordpress |
Affected
|