PoC Index

CVE-2007-4894

HIGH 7.5EPSS 3.6%

Multiple SQL injection vulnerabilities in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a allow remote attackers to execute arbitrary SQL commands via the post_type parameter to the pingback.extensions.getPingbacks method in the XMLRPC interface, and other unspecified parameters related to "early database escaping" and missing validation of "query string like parameters."

CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
3.64% chance of exploitation in the next 30 days, 89th percentile
Nuclei
critical
Published
2007-09-14
Updated
2024-08-07

Nuclei templates (1)

References

Related