First published: Wed Apr 02 2014(Updated: )
Multiple SQL injection vulnerabilities in wpf.class.php in the Mingle Forum plugin before 1.0.34 for WordPress allow remote attackers to execute arbitrary SQL commands via the id parameter in a viewtopic (1) remove_post, (2) sticky, or (3) closed action or (4) thread parameter in a postreply action to index.php.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cartpauj Mingle-forum | <=1.0.33 | |
Cartpauj Mingle-forum | =1.0.00 | |
Cartpauj Mingle-forum | =1.0.01 | |
Cartpauj Mingle-forum | =1.0.02 | |
Cartpauj Mingle-forum | =1.0.03 | |
Cartpauj Mingle-forum | =1.0.04 | |
Cartpauj Mingle-forum | =1.0.05 | |
Cartpauj Mingle-forum | =1.0.06 | |
Cartpauj Mingle-forum | =1.0.07 | |
Cartpauj Mingle-forum | =1.0.08 | |
Cartpauj Mingle-forum | =1.0.09 | |
Cartpauj Mingle-forum | =1.0.10 | |
Cartpauj Mingle-forum | =1.0.11 | |
Cartpauj Mingle-forum | =1.0.12 | |
Cartpauj Mingle-forum | =1.0.13 | |
Cartpauj Mingle-forum | =1.0.14 | |
Cartpauj Mingle-forum | =1.0.15 | |
Cartpauj Mingle-forum | =1.0.16 | |
Cartpauj Mingle-forum | =1.0.17 | |
Cartpauj Mingle-forum | =1.0.18 | |
Cartpauj Mingle-forum | =1.0.19 | |
Cartpauj Mingle-forum | =1.0.20 | |
Cartpauj Mingle-forum | =1.0.21 | |
Cartpauj Mingle-forum | =1.0.21.1 | |
Cartpauj Mingle-forum | =1.0.22 | |
Cartpauj Mingle-forum | =1.0.23 | |
Cartpauj Mingle-forum | =1.0.23.1 | |
Cartpauj Mingle-forum | =1.0.23.2 | |
Cartpauj Mingle-forum | =1.0.24 | |
Cartpauj Mingle-forum | =1.0.25 | |
Cartpauj Mingle-forum | =1.0.26 | |
Cartpauj Mingle-forum | =1.0.27 | |
Cartpauj Mingle-forum | =1.0.28 | |
Cartpauj Mingle-forum | =1.0.28.1 | |
Cartpauj Mingle-forum | =1.0.28.2 | |
Cartpauj Mingle-forum | =1.0.29 | |
Cartpauj Mingle-forum | =1.0.30 | |
Cartpauj Mingle-forum | =1.0.31 | |
Cartpauj Mingle-forum | =1.0.31.1 | |
Cartpauj Mingle-forum | =1.0.31.2 | |
Cartpauj Mingle-forum | =1.0.31.3 | |
Cartpauj Mingle-forum | =1.0.31.4 | |
Cartpauj Mingle-forum | =1.0.32 | |
Cartpauj Mingle-forum | =1.0.32.1 | |
WordPress | ||
All of | ||
Any of | ||
Cartpauj Mingle-forum | <=1.0.33 | |
Cartpauj Mingle-forum | =1.0.00 | |
Cartpauj Mingle-forum | =1.0.01 | |
Cartpauj Mingle-forum | =1.0.02 | |
Cartpauj Mingle-forum | =1.0.03 | |
Cartpauj Mingle-forum | =1.0.04 | |
Cartpauj Mingle-forum | =1.0.05 | |
Cartpauj Mingle-forum | =1.0.06 | |
Cartpauj Mingle-forum | =1.0.07 | |
Cartpauj Mingle-forum | =1.0.08 | |
Cartpauj Mingle-forum | =1.0.09 | |
Cartpauj Mingle-forum | =1.0.10 | |
Cartpauj Mingle-forum | =1.0.11 | |
Cartpauj Mingle-forum | =1.0.12 | |
Cartpauj Mingle-forum | =1.0.13 | |
Cartpauj Mingle-forum | =1.0.14 | |
Cartpauj Mingle-forum | =1.0.15 | |
Cartpauj Mingle-forum | =1.0.16 | |
Cartpauj Mingle-forum | =1.0.17 | |
Cartpauj Mingle-forum | =1.0.18 | |
Cartpauj Mingle-forum | =1.0.19 | |
Cartpauj Mingle-forum | =1.0.20 | |
Cartpauj Mingle-forum | =1.0.21 | |
Cartpauj Mingle-forum | =1.0.21.1 | |
Cartpauj Mingle-forum | =1.0.22 | |
Cartpauj Mingle-forum | =1.0.23 | |
Cartpauj Mingle-forum | =1.0.23.1 | |
Cartpauj Mingle-forum | =1.0.23.2 | |
Cartpauj Mingle-forum | =1.0.24 | |
Cartpauj Mingle-forum | =1.0.25 | |
Cartpauj Mingle-forum | =1.0.26 | |
Cartpauj Mingle-forum | =1.0.27 | |
Cartpauj Mingle-forum | =1.0.28 | |
Cartpauj Mingle-forum | =1.0.28.1 | |
Cartpauj Mingle-forum | =1.0.28.2 | |
Cartpauj Mingle-forum | =1.0.29 | |
Cartpauj Mingle-forum | =1.0.30 | |
Cartpauj Mingle-forum | =1.0.31 | |
Cartpauj Mingle-forum | =1.0.31.1 | |
Cartpauj Mingle-forum | =1.0.31.2 | |
Cartpauj Mingle-forum | =1.0.31.3 | |
Cartpauj Mingle-forum | =1.0.31.4 | |
Cartpauj Mingle-forum | =1.0.32 | |
Cartpauj Mingle-forum | =1.0.32.1 | |
WordPress |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0735 has been classified as a high severity vulnerability due to its potential for arbitrary SQL command execution.
To fix CVE-2013-0735, upgrade the Mingle Forum plugin to version 1.0.34 or later.
CVE-2013-0735 affects versions of the Mingle Forum plugin prior to 1.0.34 installed on WordPress.
Attackers can exploit CVE-2013-0735 to perform SQL injection attacks that may result in unauthorized data access or manipulation.
CVE-2013-0735 can be exploited through actions such as remove_post, sticky, closed, and postreply parameters.