mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-29 01:31:01 +00:00
19 lines
899 B
Markdown
19 lines
899 B
Markdown
### [CVE-2016-10949](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10949)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
The Relevanssi Premium plugin before 1.14.6.1 for WordPress has SQL injection with resultant unsafe unserialization.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://advisories.dxw.com/advisories/sql-injection-and-unserialization-vulnerability-in-relevanssi-premium-could-allow-admins-to-execute-arbitrary-code-in-some-circumstances/
|
|
- https://advisories.dxw.com/advisories/sql-injection-and-unserialization-vulnerability-in-relevanssi-premium-could-allow-admins-to-execute-arbitrary-code-in-some-circumstances/
|
|
|
|
#### Github
|
|
- https://github.com/ARPSyndicate/cvemon
|
|
|