CVE-2014-9178

Smarty Pants Plugins SP Project & Document Manager <2.4.1 - SQL Inj...

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in classes/ajax.php in the Smarty Pants Plugins SP Project & Document Manager plugin (sp-client-document-manager) 2.4.1 and earlier for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) vendor_email[] parameter in the email_vendor function or id parameter in the (2) download_project, (3) download_archive, or (4) remove_cat function.

Exploits (1)

exploitdb WRITEUP VERIFIED
by ITAS Team · textwebappsphp
https://www.exploit-db.com/exploits/35313

References (5)

Core 5

Scores

EPSS 0.0207
EPSS Percentile 84.0%

Details

CWE
CWE-89
Status published
Products (1)
smartypantsplugins/sp_project_\&_document_manager < 2.4.1
Published Dec 02, 2014
Tracked Since Feb 18, 2026