Vulnerabilities (CVE)

Filtered by vendor Ait-pro Subscribe
Filtered by product Bulletproof Security
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-7958 1 Ait-pro 1 Bulletproof Security 2021-12-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin before .51.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the dbhost parameter.
CVE-2014-7959 1 Ait-pro 1 Bulletproof Security 2021-12-15 6.5 MEDIUM N/A
SQL injection vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin before .51.1 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the tableprefix parameter.
CVE-2014-8749 1 Ait-pro 1 Bulletproof Security 2014-12-01 5.0 MEDIUM N/A
Server-side request forgery (SSRF) vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin before .51.1 for WordPress allows remote attackers to trigger outbound requests that authenticate to arbitrary databases via the dbhost parameter.