Lucene search

K
cveMitreCVE-2014-8586
HistoryNov 04, 2014 - 3:55 p.m.

CVE-2014-8586

2014-11-0415:55:06
CWE-89
mitre
web.nvd.nist.gov
29
cve-2014-8586
sql injection
cp multi view event calendar
wordpress
vulnerability
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.8

Confidence

Low

EPSS

0.098

Percentile

95.0%

SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.01 for WordPress allows remote attackers to execute arbitrary SQL commands via the calid parameter.

Affected configurations

Nvd
Node
cp_multi_view_event_calendar_projectcp_multi_view_event_calendarMatch1.0.1wordpress
VendorProductVersionCPE
cp_multi_view_event_calendar_projectcp_multi_view_event_calendar1.0.1cpe:2.3:a:cp_multi_view_event_calendar_project:cp_multi_view_event_calendar:1.0.1:*:*:*:wordpress:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.8

Confidence

Low

EPSS

0.098

Percentile

95.0%