Back to search
CVE-2011-1047
Published: Feb 21, 2011
Modified: Aug 6, 2024
PUBLISHED
Description
Multiple SQL injection vulnerabilities in VastHTML Forum Server (aka ForumPress) plugin 1.6.1 and 1.6.5 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) search_max parameter in a search action to index.php, which is not properly handled by wpf.class.php, (2) id parameter in an editpost action to index.php, which is not properly handled by wpf-post.php, or (3) topic parameter to feed.php.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
8099
third-party-advisory
x_refsource_SREASON
46362
vdb-entry
x_refsource_BID
20110210 HTB22852: SQL Injection in WP Forum Server wordpress plugin
mailing-list
x_refsource_BUGTRAQ
70994
vdb-entry
x_refsource_OSVDB
43306
third-party-advisory
x_refsource_SECUNIA
20110210 HTB22851: SQL Injection in WP Forum Server wordpress plugin
mailing-list
x_refsource_BUGTRAQ
70993
vdb-entry
x_refsource_OSVDB
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now