WordPress NewStatPress 漏洞列表
共找到 2 个与 WordPress NewStatPress 相关的漏洞
📅 加载漏洞趋势中...
-
CVE-2015-4062: WordPress NewStatPress 0.9.8 - SQL Injection POC
WordPress NewStatPress 0.9.8 plugin contains a SQL injection vulnerability in includes/nsp_search.php. A remote authenticated user can execute arbitrary SQL commands via the where1 parameter in the nsp_search page to wp-admin/admin.php. -
CVE-2022-0206: WordPress NewStatPress <1.3.6 - Cross-Site Scripting POC
WordPress NewStatPress plugin before 1.3.6 is susceptible to cross-site scripting. The plugin does not properly escape the whatX parameters before outputting them back in attributes. An attacker can inject arbitrary script in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.