vendor:
Wow Viral Signups
by:
TAD GROUP
9
CVSS
CRITICAL
SQL Injection
89
CWE
Product Name: Wow Viral Signups
Affected Version From: 2.1
Affected Version To: 2.1
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2017
Wow Viral Signups v2.1 WordPress Plugin SQL Injection
An unescaped parameter was found in Wow Viral Signups v2.1 (WP plugin). An attacker can exploit this vulnerability to read from the database. The POST parameter 'idsignup' is vulnerable.
Mitigation:
Input validation and escaping should be used to prevent SQL injection attacks.