PoC Index

CVE-2011-4671

HIGH 7.5EPSS 2.9%

SQL injection vulnerability in adrotate/adrotate-out.php in the AdRotate plugin 3.6.6, and other versions before 3.6.8, for WordPress allows remote attackers to execute arbitrary SQL commands via the track parameter (aka redirect URL).

CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
2.90% chance of exploitation in the next 30 days, 86th percentile
Published
2011-12-02
Updated
2024-08-07

Proof-of-concept exploits (1)

ExploitDB entries (2)

References

Related