WordPress All Video Gallery Plugin 'vid' Parameter Multiple SQL Injection Vulnerabilities
BID:56380
Info
WordPress All Video Gallery Plugin 'vid' Parameter Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 56380 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 02 2012 12:00AM |
| Updated: | Nov 02 2012 12:00AM |
| Credit: | Charlie Eriksen via Secunia |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
WordPress All Video Gallery Plugin 'vid' Parameter Multiple SQL Injection Vulnerabilities
The All Video Gallery plugin for WordPress is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
An attacker can exploit these issues to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
All Video Gallery versions prior to 1.1.0 are vulnerable.
The All Video Gallery plugin for WordPress is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
An attacker can exploit these issues to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
All Video Gallery versions prior to 1.1.0 are vulnerable.
Exploit / POC
WordPress All Video Gallery Plugin 'vid' Parameter Multiple SQL Injection Vulnerabilities
An attacker can exploit these issues using a browser.
An attacker can exploit these issues using a browser.
Solution / Fix
WordPress All Video Gallery Plugin 'vid' Parameter Multiple SQL Injection Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
WordPress All Video Gallery Plugin 'vid' Parameter Multiple SQL Injection Vulnerabilities
References:
References: