SQL injection vulnerability in mycategoryorder.php in the My Category Order plugin 2.8 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the parentID parameter in an act_OrderCategories action to wp-admin/post-new.php.
References
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 01:10
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.org/0907-exploits/wpmco-sql.txt - | |
References | () http://www.exploit-db.com/exploits/9150 - | |
References | () http://www.securityfocus.com/bid/35704 - Exploit | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/51727 - |
Information
Published : 2010-03-26 20:30
Updated : 2024-11-21 01:10
NVD link : CVE-2009-4748
Mitre link : CVE-2009-4748
CVE.ORG link : CVE-2009-4748
JSON object : View
Products Affected
wordpress
- wordpress
andrew_charlton
- my_category_order
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')