vendor:
Spider Event Calendar
by:
Manuel García Cárdenas
7,1
CVSS
HIGH
Blind SQL Injection
89
CWE
Product Name: Spider Event Calendar
Affected Version From: 1.5.51
Affected Version To: 1.5.51
Patch Exists: YES
Related CWE: N/A
CPE: a:wordpress:spider_event_calendar:1.5.51
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2017
WordPress Plugin Spider Event Calendar 1.5.51 – Blind SQL Injection
This bug was found using the portal in the files: /spider-event-calendar/calendar_functions.php and /spider-event-calendar/widget_Theme_functions.php. The parameter 'order_by' is not sanitized in /spider-event-calendar/front_end/frontend_functions.php, allowing for SQL injection. To exploit the vulnerability only is needed use the version 1.0 of the HTTP protocol to interact with the application.
Mitigation:
Update to version 1.5.52