SQL injection vulnerability in mycategoryorder.php in the My Category Order plugin 2.8 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the parentID parameter in an act_OrderCategories action to wp-admin/post-new.php.
References
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2010-03-26 20:30
Updated : 2017-09-19 01:30
NVD link : CVE-2009-4748
Mitre link : CVE-2009-4748
CVE.ORG link : CVE-2009-4748
JSON object : View
Products Affected
andrew_charlton
- my_category_order
wordpress
- wordpress
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')