Extension WordPress
Vulnérabilités WP Symposium
Cette page rassemble les failles publiées pour WP Symposium, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP Symposium
12 fiches
WP Symposium <= 15.8.1 – Reflected Cross-Site Scripting
The WP Symposium plugin through 15.8.1 for WordPress has XSS via the wp-content/plugins/wp-symposium/get_album_item.php?size parameter.
*-15.8.1
15.9
06/09/2015
WP Symposium < 15.8 – Blind SQL Injection
The WP Symposium plugin for WordPress is vulnerable to blind SQL Injection in versions before 15.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…
[*, 15.8)
15.8
10/08/2015
WP Symposium <= 15.8 – Unauthenticated SQL Injection
SQL injection vulnerability in the WP Symposium plugin before 15.8 for WordPress allows remote attackers to execute arbitrary SQL commands via the size parameter to get_album_item.php.
[*, 15.8)
15.8
09/08/2015
WP Symposium < 15.4 – SQL Injection
SQL injection vulnerability in forum.php in the WP Symposium plugin before 15.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the show parameter in the QUERY_STRING to the default URI.
[*, 15.4)
15.4
14/04/2015
WP Symposium <= 14.11 – Arbitrary File Upload
The WP Symposium plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the UploadHandler.php file in versions up to, and including, 14.11. This makes it possible for attackers to upload arbitrary…
*-14.11
15.1
11/12/2014
WP Symposium <= 14.10 – Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the WP Symposium plugin before 14.11 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) text parameter in an addComment action to ajax/profile_functions.php, (2) compose_text parameter…
*-14.10
14.11
26/11/2014
WP Symposium < 14.11 – Authenticated SQL Injection
SQL injection vulnerability in ajax/mail_functions.php in the WP Symposium plugin before 14.11 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the tray parameter in a getMailMessage action.
[*, 14.11)
14.11
26/11/2014
WP Symposium <= 13.04 – Open Redirection
Open redirect vulnerability in invite.php in the WP Symposium plugin 13.04 for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the u parameter.
*-13.04
13.05
01/08/2014
WP Symposium <= 12.11 – SQL Injections
The WP Symposium plugin for WordPress is vulnerable to various SQL Injections in versions up to, and including, 12.09 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…
*-12.11
12.12
01/08/2014
WP Symposium <= 11.11.26 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in uploadify/get_profile_avatar.php in the WP Symposium plugin before 11.12.08 for WordPress allows remote attackers to inject arbitrary web script or HTML via the uid parameter.
*-11.11.26
11.12.08
01/08/2014
WP Symposium < 13.04 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in invite.php in the WP Symposium plugin before 13.04 for WordPress allows remote attackers to inject arbitrary web script or HTML via the u parameter.
[*, 13.04)
13.04
01/08/2014
WP Symposium < 11.12.24 – Arbitrary File Upload
Multiple unrestricted file upload vulnerabilities in the WP Symposium plugin before 11.12.24 for WordPress allow remote attackers to execute arbitrary code by uploading a file with an executable extension using (1) uploadify/upload_admin_avatar.php or (2) uploadify/upload_profile_avatar.php, then accessing it…
[*, 11.12.24)
11.12.24
28/12/2011
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.