7.5
CVE-2013-1852
- EPSS 1.49%
- Veröffentlicht 05.02.2014 15:10:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
LeagueManager < 3.8.1 - SQL Injection
SQL injection vulnerability in leaguemanager.php in the LeagueManager plugin before 3.8.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the league_id parameter in the leaguemanager-export page to wp-admin/admin.php.
Mögliche Gegenmaßnahme
LeagueManager: Update to version 3.8.1, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
LeagueManager
Version
[*, 3.8.1)
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Kolja Schleich ≫ Leaguemanager SwPlatformwordpress Version <= 3.8
Kolja Schleich ≫ Leaguemanager Version1.0 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version1.1 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version1.2 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version1.2.1 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version1.2.2 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version1.3 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version1.4 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version1.4.1 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version1.4.2 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version1.5 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version2.0 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version2.1 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version2.2 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version2.3 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version2.3.1 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version2.4 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version2.4.1 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version2.5 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version2.5.1 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version2.5.2 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version2.6 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version2.6.1 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version2.6.2 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version2.6.3 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version2.7 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version2.7.1 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version2.8 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version2.9 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version2.9 Updaterc1 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version2.9 Updaterc2 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version2.9.1 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version2.9.2 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version2.9.3 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.0 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.0.1 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.0.2 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.0.3 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.0.4 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.1 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.1.1 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.1.2 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.1.3 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.1.4 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.1.5 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.1.6 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.1.7 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.1.8 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.1.9 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.2 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.2 Updaterc1 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.2.1 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.2.2 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.3 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.3.1 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.4 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.4 Updaterc2 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.4 Updaterc3 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.4.1 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.4.2 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.5 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.5.1 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.5.2 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.5.3 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.5.4 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.5.5 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.5.6 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.6 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.6.1 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.6.2 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.6.3 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.6.4 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.6.5 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.6.6 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.6.7 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.6.8 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.6.9 SwPlatformwordpress
Kolja Schleich ≫ Leaguemanager Version3.7 SwPlatformwordpress
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.49% | 0.804 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.