CVE-2013-0735

Multiple SQL injection vulnerabilities in wpf.class.php in the Mingle Forum plugin before 1.0.34 for WordPress allow remote attackers to execute arbitrary SQL commands via the id parameter in a viewtopic (1) remove_post, (2) sticky, or (3) closed action or (4) thread parameter in a postreply action to index.php.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
flexeraCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 68%
VendorProductVersion
cartpaujmingle-forum
𝑥
≤ 1.0.33
cartpaujmingle-forum
1.0.00
cartpaujmingle-forum
1.0.01
cartpaujmingle-forum
1.0.02
cartpaujmingle-forum
1.0.03
cartpaujmingle-forum
1.0.04
cartpaujmingle-forum
1.0.05
cartpaujmingle-forum
1.0.06
cartpaujmingle-forum
1.0.07
cartpaujmingle-forum
1.0.08
cartpaujmingle-forum
1.0.09
cartpaujmingle-forum
1.0.10
cartpaujmingle-forum
1.0.11
cartpaujmingle-forum
1.0.12
cartpaujmingle-forum
1.0.13
cartpaujmingle-forum
1.0.14
cartpaujmingle-forum
1.0.15
cartpaujmingle-forum
1.0.16
cartpaujmingle-forum
1.0.17
cartpaujmingle-forum
1.0.18
cartpaujmingle-forum
1.0.19
cartpaujmingle-forum
1.0.20
cartpaujmingle-forum
1.0.21
cartpaujmingle-forum
1.0.21.1
cartpaujmingle-forum
1.0.22
cartpaujmingle-forum
1.0.23
cartpaujmingle-forum
1.0.23.1
cartpaujmingle-forum
1.0.23.2
cartpaujmingle-forum
1.0.24
cartpaujmingle-forum
1.0.25
cartpaujmingle-forum
1.0.26
cartpaujmingle-forum
1.0.27
cartpaujmingle-forum
1.0.28
cartpaujmingle-forum
1.0.28.1
cartpaujmingle-forum
1.0.28.2
cartpaujmingle-forum
1.0.29
cartpaujmingle-forum
1.0.30
cartpaujmingle-forum
1.0.31
cartpaujmingle-forum
1.0.31.1
cartpaujmingle-forum
1.0.31.2
cartpaujmingle-forum
1.0.31.3
cartpaujmingle-forum
1.0.31.4
cartpaujmingle-forum
1.0.32
cartpaujmingle-forum
1.0.32.1
𝑥
= Vulnerable software versions