CVE-2014-9520: SQL Injection
Published Jan 5, 2015
·Updated
SQL injection vulnerability in execute.php in InfiniteWP Admin Panel before 2.4.4 allows remote attackers to execute arbitrary SQL commands via the historyID parameter.
Affected Software
1 affected component
InfiniteWP InfiniteWP<=2.4.3
Event History
Jan 5, 2015
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-9520?
The severity of CVE-2014-9520 is considered high due to the potential for remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2014-9520?
To fix CVE-2014-9520, upgrade to InfiniteWP Admin Panel version 2.4.4 or later.
3
Which versions are affected by CVE-2014-9520?
CVE-2014-9520 affects InfiniteWP Admin Panel versions prior to 2.4.4.
4
What causes CVE-2014-9520?
CVE-2014-9520 is caused by SQL injection vulnerabilities in the execute.php file through the historyID parameter.
5
Can CVE-2014-9520 be exploited remotely?
Yes, CVE-2014-9520 can be exploited remotely by attackers to manipulate the database.