packetstormsecurity.com
http://packetstormsecurity.com/files/151692/WordPress-Booking-Calendar-8.4.3-SQL-Injection.html CVE-2018-20556
HIGH
WordPress Plugin Booking Calendar 8.4.3 - (Authenticated) SQL Injection
Record summary
CVE-2018-20556 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
SQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the booking_id parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin Booking Calendar 8.4.3 - (Authenticated) SQL InjectionExploitDB exploitby B0UGNot analyzed1 file
References
5gist.github.com
https://gist.github.com/B0UG/a750c2c204825453e6faf898ea6d09f6 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-20556 vulners.com
https://vulners.com/exploitdb/EDB-ID:46377 46377exploit
https://www.exploit-db.com/exploits/46377