Exploitation Summary
EIP tracks 1 public exploit for CVE-2017-9429. PoCs published by Dimitrios Tsagkarakis.
AI-analyzed exploit summary This is a writeup describing a blind SQL injection vulnerability in the WordPress Event List plugin (version <= 0.7.8). The PoC demonstrates a time-based SQLi via the 'id' parameter in an authenticated admin context.
Description
SQL injection vulnerability in the Event List plugin 0.7.8 for WordPress allows an authenticated user to execute arbitrary SQL commands via the id parameter to wp-admin/admin.php.
Exploits (1)
This is a writeup describing a blind SQL injection vulnerability in the WordPress Event List plugin (version <= 0.7.8). The PoC demonstrates a time-based SQLi via the 'id' parameter in an authenticated admin context.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H