CVE-2015-2196 | Web-Dorado Spider Calendar 1.4.9 admin/ wp-admin/admin-ajax.php cat_id sql injection (EDB-36061 / ID 10350)
A vulnerability classified as critical has been found in Web-Dorado Spider Calendar 1.4.9. Affected is an unknown function of the file wp-admin/admin-ajax.php of the component admin/. The manipulation of the argument cat_id leads to sql injection.
This vulnerability is traded as CVE-2015-2196. It is possible to launch the attack remotely. Furthermore, there is an exploit available.