A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in the id GET parameter supplied to get_script/index.php, and allows an attacker to execute arbitrary SQL queries in the context of the WP database user.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/157607/WordPress-ChopSlider-3-SQL-Injection.html | Exploit Third Party Advisory VDB Entry |
http://packetstormsecurity.com/files/157655/WordPress-ChopSlider3-3.4-SQL-Injection.html | Exploit Third Party Advisory |
http://seclists.org/fulldisclosure/2020/May/26 | Mailing List Third Party Advisory |
https://github.com/idangerous/Plugins/tree/master/Chop%20Slider%203 | Third Party Advisory |
https://idangero.us/ | Product |
http://packetstormsecurity.com/files/157607/WordPress-ChopSlider-3-SQL-Injection.html | Exploit Third Party Advisory VDB Entry |
http://packetstormsecurity.com/files/157655/WordPress-ChopSlider3-3.4-SQL-Injection.html | Exploit Third Party Advisory |
http://seclists.org/fulldisclosure/2020/May/26 | Mailing List Third Party Advisory |
https://github.com/idangerous/Plugins/tree/master/Chop%20Slider%203 | Third Party Advisory |
https://idangero.us/ | Product |
Configurations
History
21 Nov 2024, 04:58
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/157607/WordPress-ChopSlider-3-SQL-Injection.html - Exploit, Third Party Advisory, VDB Entry | |
References | () http://packetstormsecurity.com/files/157655/WordPress-ChopSlider3-3.4-SQL-Injection.html - Exploit, Third Party Advisory | |
References | () http://seclists.org/fulldisclosure/2020/May/26 - Mailing List, Third Party Advisory | |
References | () https://github.com/idangerous/Plugins/tree/master/Chop%20Slider%203 - Third Party Advisory | |
References | () https://idangero.us/ - Product |
Information
Published : 2020-05-08 20:15
Updated : 2024-11-21 04:58
NVD link : CVE-2020-11530
Mitre link : CVE-2020-11530
CVE.ORG link : CVE-2020-11530
JSON object : View
Products Affected
idangero
- chop_slider
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')