Record summary

CVE-2015-2196 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

SQL injection vulnerability in Spider Event Calendar 1.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a spiderbigcalendar_month action to wp-admin/admin-ajax.php.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBWordPress Plugin Webdorado Spider Event Calendar 1.4.9 - SQL InjectionExploitDB exploitby Mateusz LachNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHWordPress Spider Calendar <=1.4.9 - SQL InjectionCVSS 7.5

WordPress Spider Calendar plugin through 1.4.9 is susceptible to SQL injection. An attacker can execute arbitrary SQL commands via the cat_id parameter in a spiderbigcalendar_month action to wp-admin/admin-ajax.php, thus making it possible to obtain sensitive information, modify data, and/or execute unauthorized administrative operations.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or complete compromise of the WordPress site.

Remediation

Fixed in version 1.4.14.

WeaknessesCWE-89
Authorstheamanrawat
Template tagstime-based-sqlicve2015cvewordpresswpsqliwpscanwp-pluginspider-event-calendarunauthedbweb-dorado
CVSS vector: CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P
CPE: cpe:2.3:a:web-dorado:spider_calendar:1.4.9:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2