CVE-2013-1852 Information
Feb 14, 2021
cve
Description
SQL injection vulnerability in leaguemanager.php in the LeagueManager plugin before 3.8.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the league_id parameter in the leaguemanager-export page to wp-admin/admin.php.
Reference
http://osvdb.org/91442 http://packetstormsecurity.com/files/120817/WordPress-LeagueManager-3.8-SQL-Injection.html http://wordpress.org/plugins/leaguemanager/changelog http://www.exploit-db.com/exploits/24789
Share on: