CVE-2018-1002000
HIGHWordPress Arigato Autoresponder & Newsletter <v2.5.1.8 - SQL Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-1002000. PoCs published by Larry W. Cashdollar.
AI-analyzed exploit summary The document describes multiple vulnerabilities (SQLi and XSS) in the WordPress plugin Arigato Autoresponder and Newsletter v2.5, including a blind SQL injection via the 'del_ids' parameter and nine reflected XSS vulnerabilities. It provides details on the vulnerable code lines and includes an example of using sqlmap to exploit the SQL injection.
Description
There is blind SQL injection in WordPress Arigato Autoresponder and Newsletter v2.5.1.8 These vulnerabilities require administrative privileges to exploit. There is an exploitable blind SQL injection vulnerability via the del_ids variable by POST request.
Exploits (1)
The document describes multiple vulnerabilities (SQLi and XSS) in the WordPress plugin Arigato Autoresponder and Newsletter v2.5, including a blind SQL injection via the 'del_ids' parameter and nine reflected XSS vulnerabilities. It provides details on the vulnerable code lines and includes an example of using sqlmap to exploit the SQL injection.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H