CVE-2014-4944
Multiple SQL injection vulnerabilities in inc/bsk-pdf-dashboard.php in the BSK PDF Manager plugin 1.3.2 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) categoryid or (2) pdfid parameter to wp-admin/admin.php.
- Affected products
- Bsk Pdf Manager
- Bannersky Bsk Pdf Manager
- = 1.3.2
- Fix
- Available
- CVSS 2.0
- 6.5 MEDIUM
- EPSS
- 3.6% (88th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2014-07-14
CVE-2014-4944 at NVD
3 known exploits for CVE-2014-4944
Proof-of-concept code and exploit modules indexed by Sploitus