CVE-2014-9519: SQL Injection
Published Jan 5, 2015
·Updated
SQL injection vulnerability in login.php in InfiniteWP Admin Panel before 2.4.3 allows remote attackers to execute arbitrary SQL commands via the email parameter.
Affected Software
1 affected component
InfiniteWP InfiniteWP<=2.4.2
Event History
Jan 5, 2015
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-9519?
CVE-2014-9519 is rated as a high severity SQL injection vulnerability.
2
How do I fix CVE-2014-9519?
To fix CVE-2014-9519, upgrade to InfiniteWP Admin Panel version 2.4.3 or later.
3
What systems are affected by CVE-2014-9519?
CVE-2014-9519 affects InfiniteWP Admin Panel versions prior to 2.4.3.
4
What type of attack does CVE-2014-9519 facilitate?
CVE-2014-9519 allows remote attackers to execute arbitrary SQL commands.
5
What parameter is exploited in CVE-2014-9519?
CVE-2014-9519 exploits the email parameter in the login.php script.