Vulnerabilities
Vulnerable Software
Wowonder:  >> Wowonder  >> 3.0.4  Security Vulnerabilities
In WoWonder 3.0.4, remote attackers can take over any account due to the weak cryptographic algorithm in recover.php. The code parameter is easily predicted from the time of day.
CVSS Score
9.8
EPSS Score
0.03
Published
2021-06-11
In WoWonder < 3.1, remote attackers can gain access to the database by exploiting a requests.php?f=search-my-followers SQL Injection vulnerability via the event_id parameter.
CVSS Score
7.5
EPSS Score
0.006
Published
2021-03-18


Contact Us

Shodan ® - All rights reserved