CVE-2014-5201

SQL injection vulnerability in the Gallery Objects plugin 0.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the viewid parameter in a go_view_object action to wp-admin/admin-ajax.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gallery_objects_project:gallery_objects:0.4:-:-:*:-:wordpress:*:*

History

No history.

Information

Published : 2014-08-12 20:55

Updated : 2015-09-08 17:53


NVD link : CVE-2014-5201

Mitre link : CVE-2014-5201

CVE.ORG link : CVE-2014-5201


JSON object : View

Products Affected

gallery_objects_project

  • gallery_objects
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')