CVE-2008-0520 Information
Feb 14, 2021
cve
Description
Multiple SQL injection vulnerabilities in main.php in the WassUp plugin 1.4 through 1.4.3 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) from_date or (2) to_date parameter to spy.php.
Reference
http://secunia.com/advisories/28702 http://www.securityfocus.com/bid/27525 http://www.vupen.com/english/advisories/2008/0365 http://www.wpwp.org/archives/warning-security-bug-in-version/ https://www.exploit-db.com/exploits/5017
Share on: