AdrotatepluginCVEs & Vulnerabilities
2 CVEs affecting Adrotateplugin products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
2 CVEs→ All vendors
Most Affected Products
adrotate 53
CVE-2014-1854HIGHpoc
SQL injection vulnerability in library/clicktracker.php in the AdRotate Pro plugin 3.9 through 3.9.5 and AdRotate Free plugin 3.9 through 3.9.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the track parameter.
27 Feb 2014
7.5
CVSS
CVE-2011-4671HIGHpoc
SQL injection vulnerability in adrotate/adrotate-out.php in the AdRotate plugin 3.6.6, and other versions before 3.6.8, for WordPress allows remote attackers to execute arbitrary SQL commands via the track parameter (aka redirect URL).
2 Dec 2011
7.5
CVSS
← PrevPage 1 / 1Next →