WordPress bbPress Plugin 'page' Parameter SQL Injection Vulnerability
BID:55364
Info
WordPress bbPress Plugin 'page' Parameter SQL Injection Vulnerability
| Bugtraq ID: | 55364 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 31 2012 12:00AM |
| Updated: | Aug 31 2012 12:00AM |
| Credit: | Dark-Puzzle |
| Vulnerable: |
WordPress bbPress 0 |
| Not Vulnerable: | |
Discussion
WordPress bbPress Plugin 'page' Parameter SQL Injection Vulnerability
The bbPress plugin is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
An attacker can exploit this issue to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The bbPress plugin is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
An attacker can exploit this issue to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Exploit / POC
WordPress bbPress Plugin 'page' Parameter SQL Injection Vulnerability
An attacker can exploit this issue using a browser.
The following example URI is available:
www.example.com/wp-content/plugins/bbpress/forum.php?id=1&page=[Inject Here]
An attacker can exploit this issue using a browser.
The following example URI is available:
www.example.com/wp-content/plugins/bbpress/forum.php?id=1&page=[Inject Here]