VYPR

Adrotate

by Adrotateplugin

CVEs (2)

  • CVE-2014-1854Feb 27, 2014
    risk 0.03cvss epss 0.06

    SQL injection vulnerability in library/clicktracker.php in the AdRotate Pro plugin 3.9 through 3.9.5 and AdRotate Free plugin 3.9 through 3.9.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the track parameter.

  • CVE-2011-4671Dec 2, 2011
    risk 0.03cvss epss 0.03

    SQL injection vulnerability in adrotate/adrotate-out.php in the AdRotate plugin 3.6.6, and other versions before 3.6.8, for WordPress allows remote attackers to execute arbitrary SQL commands via the track parameter (aka redirect URL).