Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 6 min 103 bronnen 1 kritiek 44 vandaag
CVE's Videos

← Terug naar CVE-database

CVE-2014-5180

MEDIUM · 6.5 CVSS Gepubliceerd: CWE-89

Beschrijving

SQL injection vulnerability in the videos page in the HDW Player Plugin (hdw-player-video-player-video-gallery) 2.4.2 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter in the edit action to wp-admin/admin.php.

Vendors

Hdwplayer

Affected products

Hdw-player-video-player-video-gallery

References