Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple SQL injection vulnerabilities in the Simple Ads Manager plugin before 2.7.97 for WordPress allow remote attackers to execute arbitrary SQL commands via a (1) hits[][] parameter in a sam_hits action to sam-ajax.php; the (2) cstr parameter in a load_posts action to sam-ajax-admin.php; the (3) searchTerm parameter in a load_combo_data action to sam-ajax-admin.php; or the (4) subscriber, (5) contributor, (6) author, (7) editor, (8) admin, or (9) sadmin parameter in a load_users action to sam-ajax-admin.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
WordPress Simple Ads Manager插件SQL注入漏洞
Vulnerability Description
WordPress是WordPress软件基金会的一套使用PHP语言开发的博客平台,该平台支持在PHP和MySQL的服务器上架设个人博客网站。Simple Ads Manager是其中的一个用于管理广告的插件。 WordPress Simple Ads Manager插件2.5.94版本和2.5.96版本的sam-ajax-admin.php脚本中存在SQL注入漏洞,该漏洞源于程序没有充分过滤sam_hits操作中的‘hits[][]’参数,oad_posts操作中的‘cstr’参数;load_combo
CVSS Information
N/A
Vulnerability Type
N/A