CVE-2017-9834
CRITICALWatuPRO < 5.5.1 - SQL Injection via watupro_questions Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-9834. PoCs published by Manich Koomsusi.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in WatuPRO WordPress plugin (version 5.5.1) via the 'watupro_questions' parameter. The PoC uses time-based blind SQLi to confirm the vulnerability by injecting SLEEP functions.
Description
SQL injection vulnerability in the WatuPRO plugin before 5.5.3.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the watupro_questions parameter in a watupro_submit action to wp-admin/admin-ajax.php.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in WatuPRO WordPress plugin (version 5.5.1) via the 'watupro_questions' parameter. The PoC uses time-based blind SQLi to confirm the vulnerability by injecting SLEEP functions.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H