WordPress AJAX Post Search Plugin 'the_search_function()' Function SQL Injection Vulnerability
BID:56436
Info
WordPress AJAX Post Search Plugin 'the_search_function()' Function SQL Injection Vulnerability
| Bugtraq ID: | 56436 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 08 2012 12:00AM |
| Updated: | Nov 08 2012 12:00AM |
| Credit: | Marcela Benetrix |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
WordPress AJAX Post Search Plugin 'the_search_function()' Function SQL Injection Vulnerability
The AJAX Post Search plugin for WordPress is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied input before using it in an SQL query.
An attacker can exploit this issue to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
AJAX Post Search 1.1 is vulnerable; other versions may also be affected.
The AJAX Post Search plugin for WordPress is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied input before using it in an SQL query.
An attacker can exploit this issue to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
AJAX Post Search 1.1 is vulnerable; other versions may also be affected.
Exploit / POC
WordPress AJAX Post Search Plugin 'the_search_function()' Function SQL Injection Vulnerability
An attacker can exploit this issue using a browser.
An attacker can exploit this issue using a browser.
Solution / Fix
WordPress AJAX Post Search Plugin 'the_search_function()' Function SQL Injection Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
WordPress AJAX Post Search Plugin 'the_search_function()' Function SQL Injection Vulnerability
References:
References:
- WordPress Homepage (WordPress)