Extension WordPress
Vulnérabilités Mail Masta
Cette page rassemble les failles publiées pour Mail Masta, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Mail Masta
14 fiches
Mail Masta <= 1.0 – SQL Injection via subscriber_email parameter
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/subscriber_list.php with the POST Parameter: subscriber_email.
*-1.0
Non indiqué
09/03/2017
Mail Masta Plugin <= 1.0 – SQL Injection via filter_list
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/edit_member.php with the GET Parameter: filter_list.
*-1.0
Non indiqué
05/03/2017
Mail Masta <= 1.0 – SQL Injection via id parameter
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/campaign/campaign-delete.php with the GET Parameter: id.
*-1.0
Non indiqué
05/03/2017
Mail Masta <= 1.0 – SQL Injection via id parameter
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/edit-list.php with the GET Parameter: id.
*-1.0
Non indiqué
18/02/2017
Mail Masta <= 1.0 – SQL Injection via list_id parameter
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/subscriber_list.php with the POST Parameter: list_id.
*-1.0
Non indiqué
18/02/2017
Mail Masta <= 1.0 – SQL Injection via filter_list parameter
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/add_member.php with the GET Parameter: filter_list.
*-1.0
Non indiqué
18/02/2017
Mail Masta <= 1.0 – SQL Injection via member_id parameter
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/edit_member.php with the GET Parameter: member_id.
*-1.0
Non indiqué
18/02/2017
Mail Masta <= 1.0 – SQL Injection via list_id parameter
A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/lists/csvexport.php (Unauthenticated) with the GET Parameter: list_id.
*-1.0
Non indiqué
18/02/2017
Mail Masta <= 1.0 – SQL Injection via id parameter
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/campaign/view-campaign.php with the GET Parameter: id.
*-1.0
Non indiqué
18/02/2017
Mail Masta <= 1.0 – SQL Injection via camp_id parameter
A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/campaign/count_of_send.php (Requires authentication to Wordpress admin) with the POST Parameter: camp_id.
*-1.0
Non indiqué
18/02/2017
Mail Masta <= 1.0 – SQL Injection via filter_list parameter
A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/lists/view-list.php (Requires authentication to Wordpress admin) with the GET Parameter: filter_list.
*-1.0
Non indiqué
18/02/2017
Mail Masta <= 1.0 – SQL Injection via id parameter
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/campaign/view-campaign-list.php with the GET Parameter: id.
*-1.0
Non indiqué
18/02/2017
Mail Masta <= 1.0 – SQL Injection via list_id parameter
A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/campaign_save.php (Requires authentication to Wordpress admin) with the POST Parameter: list_id.
*-1.0
Non indiqué
18/02/2017
Mail Masta <= 1.0 – Local File Inclusion
The mail-masta plugin 1.0 for WordPress has local file inclusion in count_of_send.php and csvexport.php.
*-1.0
Non indiqué
23/08/2016
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.