CVE

Id
60682  
CVE No.
CVE-2013-0735  
Status
Candidate  
Description
Multiple SQL injection vulnerabilities in wpf.class.php in the Mingle Forum plugin before 1.0.34 for WordPress allow remote attackers to execute arbitrary SQL commands via the id parameter in a viewtopic (1) remove_post, (2) sticky, or (3) closed action or (4) thread parameter in a postreply action to index.php.  
Phase
Assigned (20130102)  
Votes
None (candidate not yet proposed)  
Comments