WordSpew <= 3.71 - SQL Injection
criticalSQL injection vulnerability in wordspew-rss.php in the Wordspew plugin before 3.72 for Wordpress allows remote attackers to execute arbitrary SQL commands via the id parameter.
- CVSS:
- 9.8
- Affected:
- up to 3.71
- Fix:
- No patched version reported
- Disclosed:
- Feb 2, 2008