Security Advisory
CVE-2011-4671
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
SQL injection vulnerability in adrotate/adrotate-out.php in the AdRotate plugin 3.6.6, and other versions before 3.6.8, for WordPress allows remote attackers to execute arbitrary SQL commands via the track parameter (aka redirect URL).