CVE-2011-4671

AdRotate < 3.6.8 - SQL Injection via Track Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2011-4671. PoCs published by Miroslav Stampar.

AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in WordPress AdRotate plugin <= 3.6.6 via the 'track' parameter, which is Base64-encoded. The PoC uses a time-based blind SQL injection technique to verify the vulnerability.

Description

SQL injection vulnerability in adrotate/adrotate-out.php in the AdRotate plugin 3.6.6, and other versions before 3.6.8, for WordPress allows remote attackers to execute arbitrary SQL commands via the track parameter (aka redirect URL).

Exploits (2)

exploitdb WORKING POC VERIFIED
by Miroslav Stampar · textwebappsphp
https://www.exploit-db.com/exploits/18114

This exploit demonstrates a SQL injection vulnerability in WordPress AdRotate plugin <= 3.6.6 via the 'track' parameter, which is Base64-encoded. The PoC uses a time-based blind SQL injection technique to verify the vulnerability.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: WordPress AdRotate plugin <= 3.6.6
No auth needed
Prerequisites: WordPress installation with AdRotate plugin <= 3.6.6 · Access to the vulnerable endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Miroslav Stampar · textwebappsphp
https://www.exploit-db.com/exploits/17888

This exploit demonstrates a SQL injection vulnerability in WordPress AdRotate plugin <= 3.6.5. The vulnerability arises from improper sanitization of the 'track' parameter, allowing arbitrary SQL commands to be executed when magic_quotes is disabled.

Classification
Working Poc 100%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: WordPress AdRotate plugin <= 3.6.5
No auth needed
Prerequisites: magic_quotes must be turned off · WordPress AdRotate plugin <= 3.6.5 installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/50674
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/46814
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/18114

Scores

EPSS 0.0307
EPSS Percentile 85.9%

Details

CWE
CWE-89
Status published
Products (47)
adrotateplugin/adrotate 0.1
adrotateplugin/adrotate 0.2
adrotateplugin/adrotate 0.3
adrotateplugin/adrotate 0.4
adrotateplugin/adrotate 0.5
adrotateplugin/adrotate 0.6
adrotateplugin/adrotate 0.7
adrotateplugin/adrotate 0.7.1
adrotateplugin/adrotate 0.8
adrotateplugin/adrotate 1.0
... and 37 more
Published Dec 02, 2011
Tracked Since Feb 18, 2026