CVE-2013-3532

Spider Video Player 2.1 - SQL Injection via Theme Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2013-3532. PoCs published by Ashiyane Digital Security Team.

AI-analyzed exploit summary The exploit describes an SQL injection vulnerability in the Spider Video Player WordPress plugin due to insufficient sanitization of user-supplied data in the 'theme' parameter. The issue allows attackers to manipulate SQL queries, potentially compromising the application or database.

Description

SQL injection vulnerability in settings.php in the Web Dorado Spider Video Player plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the theme parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Ashiyane Digital Security Team · textwebappsphp
https://www.exploit-db.com/exploits/38458

The exploit describes an SQL injection vulnerability in the Spider Video Player WordPress plugin due to insufficient sanitization of user-supplied data in the 'theme' parameter. The issue allows attackers to manipulate SQL queries, potentially compromising the application or database.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: Spider Video Player plugin for WordPress 2.1
No auth needed
Prerequisites: Access to the vulnerable WordPress plugin endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/98332
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/92264
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/70763
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/83374
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/59021

Scores

EPSS 0.0539
EPSS Percentile 91.6%

Details

CWE
CWE-89
Status published
Products (1)
webdorado/spider_video_player 2.1
Published May 10, 2013
Tracked Since Feb 18, 2026