CVE-2011-4671
SQL injection vulnerability in adrotate/adrotate-out.php in the AdRotate plugin 3.6.6, and other versions before 3.6.8, for WordPress allows remote attackers to execute arbitrary SQL commands via the track parameter (aka redirect URL).
- Affected products
- Adrotate
- Adrotateplugin Adrotate
- ≤ 3.6.7, 0.1, 0.2, 0.3, 0.4, 0.5, 0.6, 0.7, 0.7.1, 0.8, 1.0, 2.0, 2.0.1, 2.1, 2.2, 2.3, 2.3.1, 2.4, 2.4.1, 2.4.2, 2.4.3, 2.4.4, 2.5, 2.5.1, 2.6, 2.6.1, 3.0, 3.0.1, 3.0.2, 3.0.3, 3.1, 3.1.1, 3.2, 3.2.1, 3.2.2, 3.3, 3.3.1, 3.4, 3.5, 3.5.1
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 2.9% (86th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2011-12-02
CVE-2011-4671 at NVD
2 known exploits for CVE-2011-4671
Proof-of-concept code and exploit modules indexed by Sploitus