7.5

CVE-2013-1852

Exploit

LeagueManager < 3.8.1 - SQL Injection

SQL injection vulnerability in leaguemanager.php in the LeagueManager plugin before 3.8.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the league_id parameter in the leaguemanager-export page to wp-admin/admin.php.
Mögliche Gegenmaßnahme
LeagueManager: Update to version 3.8.1, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Kolja Schleich ≫ Leaguemanager SwPlatform wordpress Version <= 3.8
Kolja Schleich ≫ Leaguemanager Version 1.0 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 1.1 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 1.2 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 1.2.1 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 1.2.2 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 1.3 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 1.4 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 1.4.1 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 1.4.2 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 1.5 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 2.0 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 2.1 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 2.2 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 2.3 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 2.3.1 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 2.4 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 2.4.1 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 2.5 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 2.5.1 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 2.5.2 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 2.6 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 2.6.1 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 2.6.2 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 2.6.3 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 2.7 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 2.7.1 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 2.8 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 2.9 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 2.9 Update rc1 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 2.9 Update rc2 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 2.9.1 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 2.9.2 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 2.9.3 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.0 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.0.1 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.0.2 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.0.3 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.0.4 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.1 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.1.1 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.1.2 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.1.3 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.1.4 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.1.5 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.1.6 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.1.7 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.1.8 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.1.9 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.2 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.2 Update rc1 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.2.1 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.2.2 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.3 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.3.1 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.4 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.4 Update rc2 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.4 Update rc3 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.4.1 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.4.2 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.5 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.5.1 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.5.2 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.5.3 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.5.4 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.5.5 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.5.6 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.6 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.6.1 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.6.2 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.6.3 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.6.4 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.6.5 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.6.6 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.6.7 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.6.8 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.6.9 SwPlatform wordpress
Kolja Schleich ≫ Leaguemanager Version 3.7 SwPlatform wordpress
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt LeagueManager
Version [*, 3.8.1)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.42% 0.918
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

http://osvdb.org/91442
http://packetstormsecurity.com/files/120817/WordPress-LeagueManager-3.8-SQL-Injection.html
Exploit
http://wordpress.org/plugins/leaguemanager/changelog
http://www.exploit-db.com/exploits/24789
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/ea0d1acc-d2c9-4851-9753-d87587236d7e
Third Party Advisory