Exploitation Summary
EIP tracks 1 public exploit for CVE-2014-1854. PoCs published by High-Tech Bridge SA.
AI-analyzed exploit summary The exploit demonstrates a SQL Injection vulnerability in AdRotate WordPress plugin via the 'track' HTTP GET parameter. The PoC uses a base64-encoded payload to extract the MySQL server version.
Description
SQL injection vulnerability in library/clicktracker.php in the AdRotate Pro plugin 3.9 through 3.9.5 and AdRotate Free plugin 3.9 through 3.9.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the track parameter.
Exploits (1)
The exploit demonstrates a SQL Injection vulnerability in AdRotate WordPress plugin via the 'track' HTTP GET parameter. The PoC uses a base64-encoded payload to extract the MySQL server version.