CVE-2011-5308
cdnvote < 0.4.1 - SQL Injection via cdnvote_post_id or cdnvote_point Parameter
Title source: llmDescription
Multiple SQL injection vulnerabilities in cdnvote-post.php in the cdnvote plugin before 0.4.2 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) cdnvote_post_id or (2) cdnvote_point parameter.
References (3)
Core 3
Core References
Various Sources x_refsource_confirm
http://wpsecure.net/2011/02/cdnvote-plugin/
Product x_refsource_confirm
https://plugins.trac.wordpress.org/changeset/350873/cdnvote/trunk/cdnvote-post.php
Exploit x_refsource_misc
https://www.htbridge.com/advisory/HTB22845
Scores
EPSS
0.0233
EPSS Percentile
81.8%
Details
CWE
CWE-89
Status
published
Products (1)
cdnvote_project/cdnvote
< 0.4.1
Published
Jan 01, 2015
Tracked Since
Feb 18, 2026