CVE-2014-8586: SQL Injection
Published Nov 4, 2014
·Updated
SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.01 for WordPress allows remote attackers to execute arbitrary SQL commands via the calid parameter.
Affected Software
1 affected component
Cp Multi View Event Calendar Project Cp Multi View Event Calendar=1.0.1
Event History
Nov 4, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8586?
CVE-2014-8586 has a high severity rating due to its ability to allow remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2014-8586?
To fix CVE-2014-8586, update the CP Multi View Event Calendar plugin to the latest version that addresses this vulnerability.
3
Who is affected by CVE-2014-8586?
Any WordPress installations using the CP Multi View Event Calendar plugin version 1.0.1 are affected by CVE-2014-8586.
4
What type of vulnerability is CVE-2014-8586?
CVE-2014-8586 is classified as an SQL injection vulnerability.
5
Can CVE-2014-8586 be exploited remotely?
Yes, CVE-2014-8586 can be exploited remotely by attackers through the calid parameter.