SQL injection vulnerability in the ajax_survey function in settings.php in the WordPress Survey and Poll plugin 1.1.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the survey_id parameter in an ajax_survey action to wp-admin/admin-ajax.php.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2090
Reference (s):
- BID:74890
- URL: http://www.securityfocus.com/bid/74890
- EXPLOIT-DB:36054
- URL: http://www.exploit-db.com/exploits/36054
- http://packetstormsecurity.com/files/130381/WordPress-Survey-And-Poll-1.1.7-Blind-SQL-Injection.html

