Lucene search

K
nvd[email protected]NVD:CVE-2013-3532
HistoryMay 10, 2013 - 9:55 p.m.

CVE-2013-3532

2013-05-1021:55:02
CWE-89
web.nvd.nist.gov
2

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.5

Confidence

Low

EPSS

0.002

Percentile

56.6%

SQL injection vulnerability in settings.php in the Web Dorado Spider Video Player plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the theme parameter.

Affected configurations

Nvd
Node
webdoradospider_video_playerMatch2.1
AND
wordpresswordpressMatch-
VendorProductVersionCPE
webdoradospider_video_player2.1cpe:2.3:a:webdorado:spider_video_player:2.1:*:*:*:*:*:*:*
wordpresswordpress-cpe:2.3:a:wordpress:wordpress:-:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.5

Confidence

Low

EPSS

0.002

Percentile

56.6%

Related for NVD:CVE-2013-3532