CVE-2015-4066
CVE-2015-4066
Multiple SQL injection vulnerabilities in admin/handlers.php in the GigPress plugin before 2.3.9 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) show_artist_id or (2) show_venue_id parameter in an add action in the gigpress.php page to wp-admin/admin.php.
Affected products
n/a · n/apublic PoCs found — 3
cve_referencepacketstormsecurity.com/files/132036/WordPress-GigPress-2.3.8-SQL-Injection.htmlunverifiedcve_referencewww.exploit-db.com/exploits/37109/unverifiedexploitdbwww.exploit-db.com/exploits/37109unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →